CVE-2026-37237 | vLLM up to 0.17.0 Media Fetching multimodal/inputs.py AsyncMediaIO.fetch_audio/AsyncMediaIO.fetch_image memory allocation

SecurityVulns

A vulnerability was found in vLLM up to 0.17.0 and classified as problematic. Affected is the function AsyncMediaIO.fetch_audio/AsyncMediaIO.fetch_image of the file multimodal/inputs.py of the component Media Fetching. Executing a manipulation can lead to uncontrolled memory allocation.

This vulnerability is handled as CVE-2026-37237. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More