CVE advisoryCRITICAL
CVE-2026-22778
vLLM Multimodal Endpoint Heap Leak Allows Code Execution
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in vLLM's multimodal endpoint may allow remote code execution when an invalid image is sent, by leaking heap addresses and bypassing security measures. This critical issue affects versions prior to 0.14.1.