CVE-2026-41523High· 7.5▾ TwilightA flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace mo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
0.5% → 0.9%
Last analysed / modified upstream
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace model, an attacker can achieve arbitrary code execution on the server when vLLM runs in Python optimized mode.
vllm: vLLM: Arbitrary code execution via malicious HuggingFace model — rated Important by Red Hat. Released 2026-06-22, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627 For more information visit https://access.redhat.com/errata/RHSA-2026:36005 https://access.redhat.com/errata/RHSA-2026:36005 For more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629
Workarounds / mitigations:
Affected packages:
vllm < 0.22.0Patched in:
vllm 0.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72813High· 7.5actix-files: actix-files: Denial of Service via empty Range header in GET requests (CVE-2026-72813)
CVE-2025-58188Mediumcrypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)
CVE-2026-86320High· 7.8A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true
CVE-2026-89716Medium· 4.4kernel: Linux kernel zram: Denial of Service due to improper deflate parameter validation (CVE-2026-89716)
CVE-2026-89727High· 7.0kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID (CVE-2026-89727)
CVE-2026-45819High· 7.5baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.