Insertion of Sensitive Information into Log File Affecting vllm package, versions [0.8.3,0.14.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insertion of Sensitive Information into Log File vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-VLLM-15199429
  • published4 Feb 2026
  • disclosed2 Feb 2026
  • creditBohdan Ivanenko

Introduced: 2 Feb 2026

CVE-2026-22778  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade vllm to version 0.14.1 or higher.

Overview

vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the video_url parameter, which allows remote files to be fetched and processed. An attacker can execute arbitrary commands on the server by supplying a crafted video file containing a malicious JPEG2000 frame that exploits a heap overflow in the decoder, combined with an information leak that reveals memory addresses to bypass ASLR.

Note: This is only exploitable if the deployment is serving a video model.

CVSS Base Scores

version 4.0
version 3.1