<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:41:57.920798+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-22778</id>
    <title>CVE-2026-22778 — vLLM leaks a heap address when PIL throws an error</title>
    <updated>2026-10-03T07:41:57.922721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)</p>
<p>vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-22778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4r2x-xpjr-7cvv</id>
    <title>GHSA-4r2x-xpjr-7cvv — vLLM has RCE In Video Processing</title>
    <updated>2026-10-03T07:41:57.922794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>## Summary</p>
<p>**A chain of vulnerabilities in vLLM allow Remote Code Execution (RCE):**</p>
<p>1. **Info Leak** - PIL error messages expose memory addresses, bypassing ASLR
2. **Heap Overflow** - JPEG2000 decoder in OpenCV/FFmpeg has a heap overflow that lets us hijack code execution</p>
<p>**Result:** Send a malicious video URL to vLLM Completions or Invocations **for a video model** -&gt; Execute arbitrary commands on the server</p>
<p>Completely default vLLM instance directly from pip, or docker, does not have authentication so "None" privileges are required, but even with non-default api-key enabled configuration this exploit is feasible through invocations route that allows payload to execute pre-auth.</p>
<p>Example heap target is provided, other heap targets can be exploited as well to achieve rce. Leak allows for simple ASLR bypass. Leak + heap overflow achieves RCE on versions prior to 0.14.1.</p>
<p>Deployments not serving a video model are not affected.</p>
<p>---</p>
<p>## 1. Vulnerability Overview</p>
<p>### 1.1 The Bug: JPEG2000 cdef Box Heap Overflow
The JPEG2000 decoder used by OpenCV (cv2) honors a `cdef` box that can remap color channels. When Y (luma) is mapped into the U (chroma) plane buffer, the decoder writes a large Y plane into the smaller U buffer, causing a heap overflow.</p>
<p>**Root Cause**
- `cdef` allows channel remapping (e.g., Y→U, U→Y).
- Y plane size: `W×H`; U plane size: `(W/2)×(H/2)`.
- Overflow size = `W×H - (W/2×H/2)` = `0.75 × W × H` bytes.</p>
<p>**Example (150×64)**
- Y plane: 150×64 = 9,600 b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4r2x-xpjr-7cvv"/>
  </entry>
</feed>
