CVE-2026-27765

Source
https://cve.org/CVERecord?id=CVE-2026-27765
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27765.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27765
Published
2026-08-11T17:17:56Z
Modified
2026-09-26T14:05:50Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

References

Affected packages

Git / github.com/vllm-project/vllm-gaudi

Affected ranges

Type
GIT
Repo
https://github.com/vllm-project/vllm-gaudi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Last Affected
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:intel:vllm_hardware:*:*:*:*:*:intel_gaudi:*:*",
        "cpe:2.3:a:intel:vllm_hardware:0.19.0:*:*:*:*:intel_gaudi:*:*",
        "cpe:2.3:a:intel:vllm_hardware:0.19.1:-:*:*:*:intel_gaudi:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.16.0"
        },
        {
            "introduced":  "0.19.0"
        },
        {
            "last_affected":  "0.19.0"
        },
        {
            "introduced":  "0.19.1-NA"
        },
        {
            "last_affected":  "0.19.1-NA"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

0.*
0.19.0
0.19.1-NA
v0.*
v0.10.1
v0.16.0rc0
v0.16.0rc1
v0.19.0
v0.19.0.post1
v0.19.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27765.json"