{"source":"ghsa","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/ghsa/changes.","question":"Which new security vulnerabilities / CVEs across all ecosystems were published since T, and how severe (CVSS) are they?","sample":[{"source":"ghsa","entityId":"ghsa:GHSA-6c4r-fmh3-7rh8","type":"advisory","title":"GHSA-6c4r-fmh3-7rh8 / CVE-2026-34760: vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models","summary":"MEDIUM severity. Affected: vllm.","significance":6,"detectedAt":"2026-07-18T23:42:07.013Z","effectiveDate":"2026-07-17T16:52:53Z","sourceUrl":"https://github.com/advisories/GHSA-6c4r-fmh3-7rh8","detail":{"severity":"medium","cve":"CVE-2026-34760","packages":"vllm","cvss":5.9}},{"source":"ghsa","entityId":"ghsa:GHSA-8wr5-jm2h-8r4f","type":"advisory","title":"GHSA-8wr5-jm2h-8r4f / CVE-2026-54234: vLLM has Remote DoS via Invalid Recovered Token Reinjection","summary":"HIGH severity. Affected: vllm.","significance":8,"detectedAt":"2026-07-18T23:42:07.013Z","effectiveDate":"2026-07-17T17:08:03Z","sourceUrl":"https://github.com/advisories/GHSA-8wr5-jm2h-8r4f","detail":{"severity":"high","cve":"CVE-2026-54234","packages":"vllm","cvss":7.5}},{"source":"ghsa","entityId":"ghsa:GHSA-rwxx-mrjm-wc2m","type":"advisory","title":"GHSA-rwxx-mrjm-wc2m / CVE-2026-55574: vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends","summary":"HIGH severity. Affected: vllm.","significance":8,"detectedAt":"2026-07-18T23:42:07.013Z","effectiveDate":"2026-07-17T17:10:37Z","sourceUrl":"https://github.com/advisories/GHSA-rwxx-mrjm-wc2m","detail":{"severity":"high","cve":"CVE-2026-55574","packages":"vllm","cvss":7.5}},{"source":"ghsa","entityId":"ghsa:GHSA-v82g-2437-67m2","type":"advisory","title":"GHSA-v82g-2437-67m2 / CVE-2026-55646: vLLM: Speech-to-text upload size limit is enforced after full UploadFile read","summary":"MEDIUM severity. Affected: vllm.","significance":7,"detectedAt":"2026-07-18T23:42:07.013Z","effectiveDate":"2026-07-17T17:16:17Z","sourceUrl":"https://github.com/advisories/GHSA-v82g-2437-67m2","detail":{"severity":"medium","cve":"CVE-2026-55646","packages":"vllm","cvss":6.5}},{"source":"ghsa","entityId":"ghsa:GHSA-cwxq-rc9x-2jvv","type":"advisory","title":"GHSA-cwxq-rc9x-2jvv / CVE-2026-54247: Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS","summary":"MEDIUM severity. Affected: github.com/zalando/skipper.","significance":4,"detectedAt":"2026-07-18T23:42:07.013Z","effectiveDate":"2026-07-17T18:14:08Z","sourceUrl":"https://github.com/advisories/GHSA-cwxq-rc9x-2jvv","detail":{"severity":"medium","cve":"CVE-2026-54247","packages":"github.com/zalando/skipper","cvss":4.3}}]}