---
id: CVE-2026-47155
title: >-
  vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning
  controls (CVE-2026-47155)
summary: >-
  A flaw was found in vLLM, an inference and serving engine for large language
  models (LLMs). The revision pinning controls in vLLM do not consistently apply
  to all artifacts loaded for a model. This allows a deployment configured with
  speci…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'
cvssSource: vendor
cwe:
  - CWE-829
  - CWE-345
vendor: Red Hat
product: Red Hat Enterprise Linux AI 3.3
affected:
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - ai_inference_server 3.3
  - enterprise_linux_ai 3.3
patched:
  - ai_inference_server 3.3
  - enterprise_linux_ai 3.3
published: '2026-06-22'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:14:40+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47155.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47155.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-47155'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2491580'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-47155'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47155'
  - url: >-
      https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6
  - url: 'https://github.com/vllm-project/vllm/pull/42616'
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm
  - url: 'https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59138'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59139'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60363'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62335'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2301.yaml
  - url: 'https://github.com/vllm-project/vllm'
  - url: 'https://github.com/advisories/GHSA-3ww4-5jv9-j5gm'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00249
epssPercentile: 0.16609
aliases:
  - GHSA-3ww4-5jv9-j5gm
  - PYSEC-2026-2301
ecosystem: pip
ingestedAt: '2026-07-07T15:41:59.559Z'
---

## Overview

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with specific revisions to still load dynamic code or other configuration files from an unpinned or default revision. This issue can lead to a supply-chain integrity compromise, where operators may unknowingly serve models with unreviewed or unintended behavior.

## Vendor advisories

- **RHSA-2026:59138** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59138)
- **RHSA-2026:59139** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59139)
- **RHSA-2026:60363** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60363)
- **RHSA-2026:62336** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62336)
- **RHSA-2026:62335** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62335)
- **Red Hat VEX** · Moderate · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47155.json)

**vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls** — rated Moderate by Red Hat. Released 2026-06-22, updated 2026-09-21.

Affected:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat AI Inference Server 3.3
- Red Hat Enterprise Linux AI 3.3

No fix planned:

- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI (RHOAI)

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:59138 https://access.redhat.com/errata/RHSA-2026:59138
For more information visit https://access.redhat.com/errata/RHSA-2026:59139 https://access.redhat.com/errata/RHSA-2026:59139
For more information visit https://access.redhat.com/errata/RHSA-2026:60363 https://access.redhat.com/errata/RHSA-2026:60363

Workarounds / mitigations:

- Upgrade to a vLLM build containing the fix (>= 0.22.0) when available from Red Hat. Until then, only serve models from trusted registries, pin revisions explicitly, and review nested artifacts in model repositories before deployment.

## Package advisory (CVE-2026-47155)

Affected packages:

- `vllm < 0.22.0`

Patched in:

- `vllm 0.22.0`

Source: https://osv.dev/vulnerability/GHSA-3ww4-5jv9-j5gm
