{"id":"CVE-2026-41523","title":"vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)","summary":"A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace mo…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":["CWE-617","CWE-94"],"vendor":"Red Hat","product":"Red Hat AI Inference Server 3.4","affected":["ai_inference_server","openshift_ai_rhoai","ai_inference_server 3.2","ai_inference_server 3.3","ai_inference_server 3.4","enterprise_linux_ai 3.3","enterprise_linux_ai 3.4"],"patched":["ai_inference_server 3.2","ai_inference_server 3.3","ai_inference_server 3.4","enterprise_linux_ai 3.3","enterprise_linux_ai 3.4"],"published":"2026-06-22","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:40:12+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-41523"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491582"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-41523"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41523"},{"url":"https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-q8gq-377p-jq3r"},{"url":"https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c"},{"url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"url":"https://access.redhat.com/errata/RHSA-2026:36005"},{"url":"https://access.redhat.com/errata/RHSA-2026:61629"},{"url":"https://access.redhat.com/errata/RHSA-2026:36006"},{"url":"https://access.redhat.com/errata/RHSA-2026:59138"},{"url":"https://access.redhat.com/errata/RHSA-2026:59139"},{"url":"https://access.redhat.com/errata/RHSA-2026:57380"},{"url":"https://access.redhat.com/errata/RHSA-2026:69466"},{"url":"https://access.redhat.com/errata/RHSA-2026:57389"},{"url":"https://access.redhat.com/errata/RHSA-2026:69467"},{"url":"https://access.redhat.com/errata/RHSA-2026:69469"},{"url":"https://access.redhat.com/errata/RHSA-2026:57390"},{"url":"https://access.redhat.com/errata/RHSA-2026:57387"},{"url":"https://access.redhat.com/errata/RHSA-2026:69464"},{"url":"https://access.redhat.com/errata/RHSA-2026:62336"},{"url":"https://access.redhat.com/errata/RHSA-2026:62335"},{"url":"https://access.redhat.com/errata/RHSA-2026:59151"},{"url":"https://access.redhat.com/errata/RHSA-2026:59144"},{"url":"https://github.com/vllm-project/vllm"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2300.yaml"},{"url":"https://github.com/advisories/GHSA-q8gq-377p-jq3r"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00913,"epssPercentile":0.58034,"aliases":["GHSA-q8gq-377p-jq3r","PYSEC-2026-2300"],"ecosystem":"pip","ingestedAt":"2026-06-29T14:31:47.734Z","slug":"CVE-2026-41523","body":"## Overview\n\nA flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace model, an attacker can achieve arbitrary code execution on the server when vLLM runs in Python optimized mode.\n\n## Vendor advisories\n\n- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)\n- **RHSA-2026:36005** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:36005)\n- **RHSA-2026:61629** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61629)\n- **RHSA-2026:36006** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:36006)\n- **RHSA-2026:59138** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59138)\n- **RHSA-2026:59139** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59139)\n- **RHSA-2026:57380** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57380)\n- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)\n- **RHSA-2026:57389** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57389)\n- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)\n- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)\n- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json)\n\n**vllm: vLLM: Arbitrary code execution via malicious HuggingFace model** — rated Important by Red Hat. Released 2026-06-22, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat AI Inference Server 3.2\n- Red Hat AI Inference Server 3.3\n- Red Hat AI Inference Server 3.4\n- Red Hat Enterprise Linux AI 3.3\n- Red Hat Enterprise Linux AI 3.4\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat AI Inference Server\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627\nFor more information visit https://access.redhat.com/errata/RHSA-2026:36005 https://access.redhat.com/errata/RHSA-2026:36005\nFor more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629\n\nWorkarounds / mitigations:\n\n- Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs.\n\n## Package advisory (CVE-2026-41523)\n\nAffected packages:\n\n- `vllm < 0.22.0`\n\nPatched in:\n\n- `vllm 0.22.0`\n\nSource: https://osv.dev/vulnerability/GHSA-q8gq-377p-jq3r","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}