Vulnerability  ·  2026-04-14

CVE-2026-22778: Critical vLLM RCE via Crafted Video Input

VulnerabilityHigh impactCVE-2026-22778
vLLM's video processing pipeline contains a critical RCE exploitable via a malicious video link or file, allowing unauthenticated code execution on inference servers.
Network, low complexity. Malicious video URL or upload triggers code execution during preprocessing.
Affected vLLM versions; potentially millions of inference deployments.
Patch vLLM to the latest version. Validate video sources. Sandbox inference workloads; restrict endpoint exposure.
Sources
OX Security analysiseSecurity Planet
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →