7.5highHigh
CVE-2026-41523
Vllm Vllm
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, no account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H- Weakness
- CWE-94
- Assigned by
- security-advisories@github.com
Dates
- Published
- 2026-06-22
- Last modified
- 2026-09-04
- Sources
- NVD
Affected products
- Vllm Vllm- 0.22.0
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://github.com/vllm-project/vllm/commit/b3c7ffcab82c2439726f8cb213800f6f38c023d3
- https://github.com/vllm-project/vllm/security/advisories/GHSA-q8gq-377p-jq3r
- https://huntr.com/bounties/dcb05b04-e625-41e7-adbc-bbae0cc2d64c
- https://access.redhat.com/errata/RHSA-2026:36005
- https://access.redhat.com/errata/RHSA-2026:36006
- https://access.redhat.com/errata/RHSA-2026:57380
- https://access.redhat.com/errata/RHSA-2026:57387
- https://access.redhat.com/errata/RHSA-2026:57389
- https://access.redhat.com/errata/RHSA-2026:57390
- https://access.redhat.com/errata/RHSA-2026:59138
- https://access.redhat.com/errata/RHSA-2026:59139
- https://access.redhat.com/errata/RHSA-2026:59144
- https://access.redhat.com/errata/RHSA-2026:59151
- https://access.redhat.com/errata/RHSA-2026:61627
- https://access.redhat.com/errata/RHSA-2026:61629