Inefficient regular expression complexity in vLLM - #VU139884
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the lm-format-enforcer structured output backend when compiling attacker-supplied regular expressions. A remote attacker can send a specially crafted request containing a catastrophic regular expression to cause a denial of service.
Exploitation requires the operator to have selected the lm-format-enforcer backend for structured outputs.