---
id: CVE-2026-41523
title: >-
  vllm: vLLM: Arbitrary code execution via malicious HuggingFace model
  (CVE-2026-41523)
summary: >-
  A flaw was found in vLLM, an inference and serving engine for large language
  models (LLMs). An unauthenticated attacker can exploit an assert-based
  security check during activation function loading. By publishing a malicious
  HuggingFace mo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe:
  - CWE-617
  - CWE-94
vendor: Red Hat
product: Red Hat AI Inference Server 3.4
affected:
  - ai_inference_server
  - openshift_ai_rhoai
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - enterprise_linux_ai 3.3
  - enterprise_linux_ai 3.4
patched:
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - enterprise_linux_ai 3.3
  - enterprise_linux_ai 3.4
published: '2026-06-22'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:55:32+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-41523'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2491582'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-41523'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41523'
  - url: >-
      https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-q8gq-377p-jq3r
  - url: 'https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
  - url: 'https://access.redhat.com/errata/RHSA-2026:36005'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61629'
  - url: 'https://access.redhat.com/errata/RHSA-2026:36006'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59138'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59139'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57380'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57389'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57390'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62335'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59151'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59144'
  - url: 'https://github.com/vllm-project/vllm'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2300.yaml
  - url: 'https://github.com/advisories/GHSA-q8gq-377p-jq3r'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00913
epssPercentile: 0.5841
aliases:
  - GHSA-q8gq-377p-jq3r
  - PYSEC-2026-2300
ecosystem: pip
ingestedAt: '2026-06-29T14:31:47.734Z'
---

## Overview

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace model, an attacker can achieve arbitrary code execution on the server when vLLM runs in Python optimized mode.

## Vendor advisories

- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)
- **RHSA-2026:36005** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:36005)
- **RHSA-2026:61629** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61629)
- **RHSA-2026:36006** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:36006)
- **RHSA-2026:59138** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59138)
- **RHSA-2026:59139** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59139)
- **RHSA-2026:57380** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57380)
- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)
- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)
- **RHSA-2026:70979** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70979)
- **RHSA-2026:57389** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57389)
- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI) · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41523.json)
- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)
- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)

**vllm: vLLM: Arbitrary code execution via malicious HuggingFace model** — rated Important by Red Hat. Released 2026-06-22, updated 2026-09-24.

Affected:

- Red Hat AI Inference Server
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4
- Red Hat Enterprise Linux AI 3.3
- Red Hat Enterprise Linux AI 3.4

No fix planned:

- Red Hat AI Inference Server
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat AI Inference Server
- Red Hat OpenShift AI (RHOAI)

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627
For more information visit https://access.redhat.com/errata/RHSA-2026:36005 https://access.redhat.com/errata/RHSA-2026:36005
For more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629

Workarounds / mitigations:

- Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs.

## Package advisory (CVE-2026-41523)

Affected packages:

- `vllm < 0.22.0`

Patched in:

- `vllm 0.22.0`

Source: https://osv.dev/vulnerability/GHSA-q8gq-377p-jq3r
