New detection content has been published for CVE-2026-22778, an information disclosure flaw in vLLM multimodal OpenAI-compatible servers that can expose a Python BytesIO heap address in error messages. The bug is triggered when a malformed image is submitted to a multimodal endpoint, causing Pillow-related exceptions such as UnidentifiedImageError to return internal object representations containing 0x-style memory addresses. The leak affects vulnerable versions through vLLM 0.14.0 and was sanitized in vLLM 0.14.1, where the sanitize_message handling prevents the address disclosure.
Rapid7 added a Metasploit auxiliary scanner to identify exposed servers by reading the /version banner, enumerating models via /v1/models, and sending a single benign malformed image request to test for the leak without reaching the reported JPEG2000 heap-overflow path. ProjectDiscovery also published a Nuclei template for the same issue, targeting endpoints such as POST /v1/chat/completions and checking for the characteristic HTTP 400 response and leaked heap-address patterns. The flaw is significant because the disclosed address can help defeat ASLR as an early stage in a potential remote code execution chain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Nuclei template pull request was created to detect the vLLM multimodal heap-address information leak tracked as CVE-2026-22778, targeting the affected API behavior around multimodal request handling.
A Metasploit auxiliary scanner module was added to detect vLLM OpenAI-compatible servers vulnerable to CVE-2026-22778 by querying version and model endpoints and sending a malformed image to test for the leak.
The references state that vLLM 0.14.1 and later sanitize the multimodal error message path, preventing the Python BytesIO heap-address leak associated with CVE-2026-22778.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.