CVE-2026-55574: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string di...
Added to the CISA Known Exploited Vulnerabilities catalog on 06 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the str...
Required action: Review and patch if applicable to your AI infrastructure.