A vulnerability was found in vllm-project vllm up to 0.19.x . It has been declared as problematic . This affects the function image_grid_thw/video_grid_thw of the component Placeholder Handler . Such manipulation leads to improper validation of array index. This vulnerability is traded as CVE-2026-44222 . The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.