Vulnerabilities · 7h ago

Rapid7 ships a vLLM leak scanner

Rapid7 added a Metasploit auxiliary scanner for CVE-2026-22778, a vLLM multimodal information leak that shows up when a malformed image reaches the endpoint. The module detects OpenAI-compatible vLLM servers affected by the bug, alongside a grab bag of unrelated new modules in the same release.

The flaw is simple: send an invalid image to the multimodal path and PIL returns an error that includes a heap address instead of failing cleanly. That memory clue can help line up a later heap overflow, so the scanner lowers the effort needed to find servers that are worth chaining into deeper exploitation.

For teams running exposed multimodal vLLM services, the change matters because the leak is now easy to fingerprint at scale, not just a theoretical bug in a code path. It also means automated tooling can separate likely targets from noise before any exploit chain is built.

CVE-2026-22778

NVD KEV

CVSS 9.8 CRITICAL: vLLM is an inference and serving engine for large language models (LLMs). EPSS 11% (96th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-09

Editions

Related stories