CVE-2026-47155Medium· 6.5▾ SunlitA flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with speci…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.1%
0.1% → 0.2%
Last analysed / modified upstream
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with specific revisions to still load dynamic code or other configuration files from an unpinned or default revision. This issue can lead to a supply-chain integrity compromise, where operators may unknowingly serve models with unreviewed or unintended behavior.
vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls — rated Moderate by Red Hat. Released 2026-06-22, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:59138 https://access.redhat.com/errata/RHSA-2026:59138 For more information visit https://access.redhat.com/errata/RHSA-2026:59139 https://access.redhat.com/errata/RHSA-2026:59139 For more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363
Workarounds / mitigations:
Affected packages:
vllm < 0.22.0Patched in:
vllm 0.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71576High· 8.5A flaw was found in multicluster-global-hub
CVE-2026-49834Medium· 5.9github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)
CVE-2026-48815Medium· 5.9sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)
CVE-2026-32597High· 7.5PyJWT is a JSON Web Token implementation in Python
CVE-2026-26007Medium· 6.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt