CVE-2026-7141
medium
CVSS v4
2.9
CVSS v3
5.6
VIR risk
5.6
Description
vLLM makes Use of Uninitialized Resource
Predictions
Exploit likelihood
66%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| vllm | vllm | {"endIncluding":"0.19.0"} | |
References
- https://github.com/AjAnubolu/vllm/commit/1ad67864c0c20f167929e64c875f5c28e1aad9fd
- https://github.com/vllm-project/vllm/issues/39146
- https://github.com/vllm-project/vllm/issues/39146#issue-4215090365
- https://github.com/vllm-project/vllm/pull/39283
- https://vuldb.com/submit/801297
- https://vuldb.com/vuln/359740
- https://vuldb.com/vuln/359740/cti
- https://nvd.nist.gov/vuln/detail/CVE-2026-7141
- https://github.com/advisories/GHSA-x368-4g9h-fvv4
CWEs
CWE-908
💬 Discuss CVE-2026-7141 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.