{"id":"CGA-qh5r-mq94-mpg4","modified":"2026-09-12T16:12:19.852136661Z","published":"2026-03-27T00:13:27Z","upstream":["CVE-2026-56340","GHSA-78fp-cf4h-g36p","GHSA-mcmc-2m55-j8jj"],"references":[{"type":"WEB","url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-mcmc-2m55-j8jj"},{"type":"WEB","url":"https://github.com/vllm-project/vllm/pull/30649"},{"type":"PACKAGE","url":"https://github.com/vllm-project/vllm"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-56340"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491060"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-250.yaml"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56340.json"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vllm-denial-of-service-via-unvalidated-multimodal-embeddings"}],"affected":[{"package":{"name":"tritonserver-backend-vllm-cuda-12.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tritonserver-backend-vllm-cuda-12.9?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2026-03-27T00:13:27Z","component_name":"vllm","component_version":"0.10.2+cu129","component_type":"python","component_location":"/opt/tritonserver/venv/lib/python3.12/site-packages/vllm-0.10.2+cu129.dist-info/METADATA","component_purl":"pkg:pypi/vllm@0.10.2%2Bcu129","latest_event_status":"detection"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-qh5r-mq94-mpg4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}