A vulnerability was found in vLLM and classified as critical. The affected element is an unknown function of the component Activation. Executing a manipulation can lead to code injection.

This vulnerability is tracked as CVE-2026-41523. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.