CVE-2026-92365
Deferred
Deferred - Pending Action
BaseFortify
Vulnerability report for CVE-2026-92365, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-22
Assigner: VulDB
Description
Description
A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vllm-project | vllm | 0.1 |
| vllm-project | vllm | 0.2 |
| vllm-project | vllm | 0.3 |
| vllm-project | vllm | 0.4 |
| vllm-project | vllm | 0.5 |
| vllm-project | vllm | 0.6 |
| vllm-project | vllm | 0.7 |
| vllm-project | vllm | 0.8 |
| vllm-project | vllm | 0.9 |
| vllm-project | vllm | 0.10 |
| vllm-project | vllm | 0.11 |
| vllm-project | vllm | 0.12 |
| vllm-project | vllm | 0.13 |
| vllm-project | vllm | 0.14 |
| vllm-project | vllm | 0.15 |
| vllm-project | vllm | 0.16 |
| vllm-project | vllm | 0.17 |
| vllm-project | vllm | 0.18 |
| vllm-project | vllm | 0.19 |
| vllm-project | vllm | 0.20 |
| vllm-project | vllm | 0.21 |
| vllm-project | vllm | 0.22 |
| vllm-project | vllm | 0.23 |
| vllm-project | vllm | 0.24 |
| vllm-project | vllm | 0.25 |
| vllm-project | vllm | 0.26 |
| vllm-project | vllm | 0.27 |
| vllm-project | vllm | 0.28 |
| vllm-project | vllm | 0.29.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-404 | The product does not release or incorrectly releases a resource before it is made available for re-use. |
| CWE-407 | An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached. |