CVE-2026-105775
Last modified
CVE-2026-105775 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| vllm-project | vLLM | 0.1; 0.2; 0.3; 0.4; 0.5; 0.6; 0.7; 0.8; 0.9; 0.10; 0.11; 0.12; 0.13; 0.14; 0.15; 0.16; 0.17; 0.18; 0.19; 0.20; 0.21; 0.22; 0.23; 0.24; 0.25; 0.26; 0.27; 0.28; 0.29; 0.30; 0.31.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-105775?
How severe is CVE-2026-105775?
How do I fix CVE-2026-105775?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105764Immich is a high-performance self-hosted photo and video man…7.7
- CVE-2026-105766Use of the backend-facing $scheme variable in the trailing-s…3.1
- CVE-2026-105767Improper Neutralization of Special Elements used in an OS Co…3.3
- CVE-2026-105768apko allows users to build and publish OCI container images …6.3
- CVE-2026-10577A security issue exists within the 1715-AENTR EtherNet/IP Ad…10
- CVE-2026-105773Canimaan Software ClamXAV versions 3.3 - 3.11 contains a loc…7
- CVE-2026-105776A flaw has been found in bhagya3929 Employee-Movement-Tracki…7.3
- CVE-2026-105778A vulnerability has been found in Tenda AC5 02.03.01.111_mul…9.9
- CVE-2026-105782Scrapy is a high-level web crawling and scraping framework f…7.5
- CVE-2026-105783Joplin is an open source note-taking and to-do application t…8
- CVE-2026-105784Joplin is an open source note-taking and to-do application t…4.6
- CVE-2026-105785Joplin is an open source note-taking and to-do application t…4.8
Are you affected by CVE-2026-105775?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
