CVE-2026-24779 | vLLM up to 0.14.0 MediaConnector server-side request forgery (GHSA-qh4c-xf7m-gxfc / EUVD-2026-4711)
A vulnerability marked as critical has been reported in vLLM up to 0.14.0. This vulnerability affects the function MediaConnector. Performing a manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-24779. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.