CVE-2026-27765
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in vLLM Hardware Plugin for Intel Gaudi

Vulnerability report for CVE-2026-27765, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Intel Corporation

Description

Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel vllm_hardware_plugin to 0.16.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation issue in the vLLM Hardware Plugin for Intel Gaudi software before version 0.16.0. It allows a denial of service attack by an authorized adversary with authenticated access. The attack requires low complexity and no special internal knowledge, occurring via local access without user interaction.

Detection Guidance

This vulnerability involves improper input validation in the vLLM Hardware Plugin for Intel Gaudi software before version 0.16.0. Detection requires checking the installed version of the plugin. Use commands like 'pip show vllm-hardware-plugin' or inspect version files in the plugin directory to verify if the version is below 0.16.0.

Impact Analysis

This vulnerability may lead to a denial of service, causing the affected system to become unavailable. It does not directly impact confidentiality or integrity but can severely disrupt system availability, potentially affecting operations dependent on the vulnerable software.

Compliance Impact

This vulnerability primarily impacts system availability due to potential denial of service. While it does not directly affect confidentiality or integrity, availability issues could indirectly impact compliance with standards like GDPR or HIPAA that require timely access to data and systems. However, specific compliance impacts depend on system configuration and use case.

Mitigation Strategies

Upgrade the vLLM Hardware Plugin for Intel Gaudi to version 0.16.0 or later immediately. Apply patches or updates provided by Intel to address the improper input validation issue. Ensure no unauthorized users have access to authenticated environments where this plugin is used.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27765. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart