<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:22:09.740651+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337493</id>
    <title>EUVD-2026-337493</title>
    <updated>2026-10-03T05:22:10.063996+00:00</updated>
    <content>EUVD-2026-337493</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22778</id>
    <title>fkie_cve-2026-22778</title>
    <updated>2026-10-03T05:22:10.064046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4r2x-xpjr-7cvv</id>
    <title>GHSA-4r2x-xpjr-7cvv — vLLM has RCE In Video Processing</title>
    <updated>2026-10-03T05:22:10.064082+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>## Summary</p>
<p>**A chain of vulnerabilities in vLLM allow Remote Code Execution (RCE):**</p>
<p>1. **Info Leak** - PIL error messages expose memory addresses, bypassing ASLR
2. **Heap Overflow** - JPEG2000 decoder in OpenCV/FFmpeg has a heap overflow that lets us hijack code execution</p>
<p>**Result:** Send a malicious video URL to vLLM Completions or Invocations **for a video model** -&gt; Execute arbitrary commands on the server</p>
<p>Completely default vLLM instance directly from pip, or docker, does not have authentication so "None" privileges are required, but even with non-default api-key enabled configuration this exploit is feasible through invocations route that allows payload to execute pre-auth.</p>
<p>Example heap target is provided, other heap targets can be exploited as well to achieve rce. Leak allows for simple ASLR bypass. Leak + heap overflow achieves RCE on versions prior to 0.14.1.</p>
<p>Deployments not serving a video model are not affected.</p>
<p>---</p>
<p>## 1. Vulnerability Overview</p>
<p>### 1.1 The Bug: JPEG2000 cdef Box Heap Overflow
The JPEG2000 decoder used by OpenCV (cv2) honors a `cdef` box that can remap color channels. When Y (luma) is mapped into the U (chroma) plane buffer, the decoder writes a large Y plane into the smaller U buffer, causing a heap overflow.</p>
<p>**Root Cause**
- `cdef` allows channel remapping (e.g., Y→U, U→Y).
- Y plane size: `W×H`; U plane size: `(W/2)×(H/2)`.
- Overflow size = `W×H - (W/2×H/2)` = `0.75 × W × H` bytes.</p>
<p>**Example (150×64)**
- Y plane: 150×64 = 9,600 b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4r2x-xpjr-7cvv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-565</id>
    <title>PYSEC-2026-565 — vLLM has RCE In Video Processing</title>
    <updated>2026-10-03T05:22:10.064159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>## Summary</p>
<p>**A chain of vulnerabilities in vLLM allow Remote Code Execution (RCE):**</p>
<p>1. **Info Leak** - PIL error messages expose memory addresses, bypassing ASLR
2. **Heap Overflow** - JPEG2000 decoder in OpenCV/FFmpeg has a heap overflow that lets us hijack code execution</p>
<p>**Result:** Send a malicious video URL to vLLM Completions or Invocations **for a video model** -&gt; Execute arbitrary commands on the server</p>
<p>Completely default vLLM instance directly from pip, or docker, does not have authentication so "None" privileges are required, but even with non-default api-key enabled configuration this exploit is feasible through invocations route that allows payload to execute pre-auth.</p>
<p>Example heap target is provided, other heap targets can be exploited as well to achieve rce. Leak allows for simple ASLR bypass. Leak + heap overflow achieves RCE on versions prior to 0.14.1.</p>
<p>Deployments not serving a video model are not affected.</p>
<p>---</p>
<p>## 1. Vulnerability Overview</p>
<p>### 1.1 The Bug: JPEG2000 cdef Box Heap Overflow
The JPEG2000 decoder used by OpenCV (cv2) honors a `cdef` box that can remap color channels. When Y (luma) is mapped into the U (chroma) plane buffer, the decoder writes a large Y plane into the smaller U buffer, causing a heap overflow.</p>
<p>**Root Cause**
- `cdef` allows channel remapping (e.g., Y→U, U→Y).
- Y plane size: `W×H`; U plane size: `(W/2)×(H/2)`.
 - Overflow size = `W×H - (W/2×H/2)` = `0.75 × W × H` bytes.</p>
<p>**Example (150×64)**
 - Y plane: 150×64 = 9,60…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19712</id>
    <title>RHSA-2026:19712 — Red Hat Security Advisory: RHOAI 3.3.3 - Red Hat OpenShift AI</title>
    <updated>2026-10-03T05:22:10.064229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vllm: Server Side request forgery (SSRF) in MediaConnector node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing react-router: @remix-run/router: React Router XSS Vulnerability golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate vllm: VLLM deserialization vulnerability leading to DoS and potential RCE axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization glob: glob: Command Injection Vulnerability via Malicious Filenames node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion vllm: vLLM: Remote Code Execution via malicious model configuration urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability lodash: lodash: Arbitrary code execution via untrusted input in template imports urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming A…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0287</id>
    <title>WID-SEC-W-2026-0287 — vllm: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-03T05:22:10.064323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0287"/>
  </entry>
</feed>
