CVE-2026-92365

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.

  • Published Sep 16, 2026
  • CVSS 5.3 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-92365 at the National Vulnerability Database