CVE-2026-105759 | vllm-project vllm up to 0.29.x track_http_metrics middleware Family::get_or_create resource consumption (EUVD-2026-92850)

SecurityVulns

A vulnerability classified as problematic has been found in vllm-project vllm up to 0.29.x. Affected by this vulnerability is the function Family::get_or_create of the component track_http_metrics middleware. Performing a manipulation results in resource consumption.

This vulnerability was named CVE-2026-105759. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More