CVE-2026-92365
A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
- Published Sep 16, 2026
- CVSS 5.3 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)