Uninitialized Resource Vulnerability in vllm by vllm-project
CVE-2026-7141
Key Information:
- Vendor
vllm-project
- Status
- Vendor
- CVE Published:
- 27 April 2026
Badges
What is CVE-2026-7141?
A vulnerability was identified in the vllm library, affecting versions up to 0.19.0, specifically within the has_mamba_layers function of the KV Block Handler component. This issue stems from uninitialized resources, which could potentially enable remote exploitation. Although the complexity of carrying out an attack is high, the exploitability has been publicly disclosed. A patch has been introduced, allowing users to mitigate this vulnerability effectively.
Affected Version(s)
vllm 0.1
vllm 0.2
vllm 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
