ADVISORY UNAUTH-2026-0039
TYPE cve
PRODUCT vLLM
SEVERITY CRITICAL
vLLM CVE-2026-22778
published 2026-08-05 · updated 2026-08-05
Why it matters
Remote code execution via the video-processing path of multimodal endpoints. Only deployments actually serving a video model are affected, but the exploit works even when the optional API key is configured.
Affected versions
- >=0.8.3,<0.14.1
Fixed in: 0.14.1
Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29.
Fix it
References
Cite this record
unauth.dev advisory UNAUTH-2026-0039 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0039. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.