<Vulnerability name="CVE-2026-55574">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-06T20:05:31</PublicDate>
    <Bugzilla id="2497509" url="https://bugzilla.redhat.com/show_bug.cgi?id=2497509" xml:lang="en:us">
vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1333</CWE>
    <Details xml:lang="en:us" source="Mitre">
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string reaches the regex compiler with no guard, and in the outlines backend the validation step blocks structural issues such as lookarounds and backreferences but performs no complexity analysis, so a pattern with nested quantifiers passes all checks and causes exponential state-space expansion, allowing a single request containing an adversarial regex to hang an inference worker indefinitely and deny service. This issue is fixed in version 0.24.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the structured_outputs.regex API parameter. This adversarial regex, containing nested quantifiers, can cause an exponential expansion of the state-space in the grammar compiler, leading to an inference worker hanging indefinitely. This results in a Denial of Service (DoS) for the affected system.
    </Details>
    <Statement xml:lang="en:us">
An Important denial of service vulnerability exists in vLLM, as utilized within Red Hat AI Inference Server and Red Hat OpenShift AI. This flaw allows a remote, unauthenticated attacker to cause an inference worker to hang indefinitely by submitting a specially crafted regular expression to the structured outputs API. The absence of complexity analysis for nested quantifiers in the regex compiler leads to an exponential state-space expansion, resulting in prolonged service disruption.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.2::el9">
        <ProductName>Red Hat AI Inference Server 3.2</ProductName>
        <ReleaseDate>2026-08-31T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:61627">RHSA-2026:61627</Advisory>
        <Package name="rhaiis/vllm-cuda-rhel9">rhaiis/vllm-cuda-rhel9:1787860580</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.2::el9">
        <ProductName>Red Hat AI Inference Server 3.2</ProductName>
        <ReleaseDate>2026-08-31T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:61629">RHSA-2026:61629</Advisory>
        <Package name="rhaiis/vllm-rocm-rhel9">rhaiis/vllm-rocm-rhel9:1787884873</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.3::el9">
        <ProductName>Red Hat AI Inference Server 3.3</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60363">RHSA-2026:60363</Advisory>
        <Package name="rhaiis/vllm-spyre-rhel9">rhaiis/vllm-spyre-rhel9:1787161776</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.4::el9">
        <ProductName>Red Hat AI Inference Server 3.4</ProductName>
        <ReleaseDate>2026-09-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:69464">RHSA-2026:69464</Advisory>
        <Package name="rhaii/vllm-spyre-rhel9">rhaii/vllm-spyre-rhel9:1789681201</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.4::el9">
        <ProductName>Red Hat AI Inference Server 3.4</ProductName>
        <ReleaseDate>2026-09-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:69466">RHSA-2026:69466</Advisory>
        <Package name="rhaii/vllm-cpu-rhel9">rhaii/vllm-cpu-rhel9:1789681128</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.4::el9">
        <ProductName>Red Hat AI Inference Server 3.4</ProductName>
        <ReleaseDate>2026-09-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:69467">RHSA-2026:69467</Advisory>
        <Package name="rhaii/vllm-cuda-rhel9">rhaii/vllm-cuda-rhel9:1789681126</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ai_inference_server:3.4::el9">
        <ProductName>Red Hat AI Inference Server 3.4</ProductName>
        <ReleaseDate>2026-09-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:69469">RHSA-2026:69469</Advisory>
        <Package name="rhaii/vllm-rocm-rhel9">rhaii/vllm-rocm-rhel9:1789681126</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:ai_inference_server:3">
        <ProductName>Red Hat AI Inference Server</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>rhaiis/vllm-neuron-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ai_inference_server:3">
        <ProductName>Red Hat AI Inference Server</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>rhaiis/vllm-tpu-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ai_inference_server:3">
        <ProductName>Red Hat AI Inference Server</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>rhaii/vllm-gaudi-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ai_inference_server:3">
        <ProductName>Red Hat AI Inference Server</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>rhaii/vllm-neuron-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ai_inference_server:3">
        <ProductName>Red Hat AI Inference Server</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>rhaii/vllm-tpu-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-aws-cuda-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-azure-cuda-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-azure-rocm-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-cuda-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-gaudi-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-gcp-cuda-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhelai3/bootc-rocm-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-kserve-agent-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-kserve-controller-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-kserve-router-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-kserve-storage-initializer-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-llm-d-kv-cache-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhoai/odh-vllm-gaudi-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-55574
https://nvd.nist.gov/vuln/detail/CVE-2026-55574
https://github.com/vllm-project/vllm/commit/2b3006076c5e9bc4cda9e03e3641388de3c5c286
https://github.com/vllm-project/vllm/pull/45118
https://github.com/vllm-project/vllm/security/advisories/GHSA-rwxx-mrjm-wc2m
    </References>
</Vulnerability>