System running
Last check: 2026-09-29 03:27:30 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-22778

Severity
CRITICAL
CVSS Score
9.8
Description

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1....

PoCs for CVE-CVE-2026-22778

EXPLOIT-CVE-2026-22778
General Python 0
joaovicdev 2026-09-05
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources