<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:25:41.250593+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329193</id>
    <title>EUVD-2026-329193</title>
    <updated>2026-10-03T00:25:41.260483+00:00</updated>
    <content>EUVD-2026-329193</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329193"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47155</id>
    <title>fkie_cve-2026-47155</title>
    <updated>2026-10-03T00:25:41.260518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3ww4-5jv9-j5gm</id>
    <title>GHSA-3ww4-5jv9-j5gm — vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors</title>
    <updated>2026-10-03T00:25:41.260554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>### Summary</p>
<p>vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies `--revision` or `--code-revision` can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision.</p>
<p>This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision.</p>
<p>### Details</p>
<p>The expected invariant is:</p>
<p>&gt; When a vLLM operator supplies a model or code revision pin, every code, config, processor, weight file, side weight, and same-repository subfolder artifact loaded as part of that model should resolve under that pin unless vLLM exposes and enforces a separate explicit pin for that artifact.</p>
<p>Current `main` was verified affected at commit `3795d7acf431980e62e738493f437ae2a51549da`.</p>
<p>Affected source boundaries:</p>
<p>- `vllm/model_executor/models/registry.py:1045-1051` and `:1058-1064`
  - `_try_resolve_transformers()` passes `revision=model_config.revision` and `trust_remote_code=model_config.trust_remote_code`, but omits `code_revision=model_config.code_revision` for external `auto_map` dynamic module imports.
- `vllm/model_executor/model_loader/gguf_loader.py:58-60`
  - The direct-file GGUF form `repo/file.gguf` calls `hf_hub_download(repo_id=repo_id, filename=filename)` without pas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3ww4-5jv9-j5gm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2301</id>
    <title>PYSEC-2026-2301</title>
    <updated>2026-10-03T00:25:41.260621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:59138</id>
    <title>RHSA-2026:59138 — Red Hat Security Advisory: Red Hat AI Inference Server 3.3.6 (CUDA)</title>
    <updated>2026-10-03T00:25:41.260645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vllm: vLLM: Arbitrary code execution via malicious HuggingFace model vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls vllm: vLLM: Information disclosure via integer truncation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:59138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1889</id>
    <title>WID-SEC-W-2026-1889 — vllm: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-03T00:25:41.260666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vllm ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1889"/>
  </entry>
</feed>
