A vulnerability was found in vllm-project vllm 0.19.0 and classified as problematic. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service.

This vulnerability is referenced as CVE-2026-9540. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The pull request to fix this issue awaits acceptance.