CVE-2026-69147 | vllm-project vLLM up to 0.27.x Video Decoder MediaConnector.fetch_video media_io_kwargs.video.video_backend allocation of resources

SecurityVulns

A vulnerability, which was classified as problematic, was found in vllm-project vLLM up to 0.27.x. This issue affects the function MediaConnector.fetch_video of the component Video Decoder. Such manipulation of the argument media_io_kwargs.video.video_backend leads to allocation of resources.

This vulnerability is listed as CVE-2026-69147. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More