CVE detail
CVE-2026-22778
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
15 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22778.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 2, 2026, 11:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2436113bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/security/cve/CVE-2026-22778access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:3782access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:3713access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:3462access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:3461access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30089access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30088access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30087access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:19712access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 2, 2026, 11:16 PM No excerpt available.
Exploitgithub.comFeb 2, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comFeb 2, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comFeb 2, 2026, 11:16 PMNo excerpt available.
Exploitgithub.comFeb 2, 2026, 11:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-25687CVSS 4.3 · Medium
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247…
- CVE-2022-31047CVSS 5.3 · Medium
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. dat…
- CVE-2020-25640CVSS 5.3 · Medium
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in…
- CVE-2019-7612CVSS 9.8 · Critical
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash config…
- CVE-2026-54236CVSS 5.3 · Medium
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips ob…
- CVE-2026-56620CVSS 4.3 · Medium
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.