<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:35:41 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-41523 — vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-41523</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server 3.4, Red Hat Enterprise Linux AI 3.3, Red Hat Enterprise Linux AI 3.4, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM&amp;#39;s activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server 3.4, Red Hat Enterprise Linux AI 3.3, Red Hat Enterprise Linux AI 3.4, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI)&lt;/p&gt;
&lt;p&gt;vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM&amp;#39;s activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-41523</guid>
    </item>
    <item>
      <title>GHSA-q8gq-377p-jq3r — vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q8gq-377p-jq3r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An `assert`-based security check in vLLM&amp;#39;s activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (`python -O` or `PYTHONOPTIMIZE=1`).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;vLLM uses an `assert` statement at [`vllm/model_executor/layers/pooler/activations.py:48`](https://github.com/vllm-project/vllm/blob/main/vllm/model_executor/layers/pooler/activations.py#L48) as its sole security control to restrict which activation functions can be loaded from a HuggingFace model&amp;#39;s `config.json`:&lt;/p&gt;
&lt;p&gt;```python
# vllm/model_executor/layers/pooler/activations.py:35-53
function_name: str | None = None
if (
    hasattr(config, &amp;#34;sentence_transformers&amp;#34;)
    and &amp;#34;activation_fn&amp;#34; in config.sentence_transformers
):
    function_name = config.sentence_transformers[&amp;#34;activation_fn&amp;#34;]
elif (
    hasattr(config, &amp;#34;sbert_ce_default_activation_function&amp;#34;)
    and config.sbert_ce_default_activation_function is not None
):
    function_name = config.sbert_ce_default_activation_function&lt;/p&gt;
&lt;p&gt;if function_name is not None:
    assert function_name.startswith(&amp;#34;torch.nn.modules.&amp;#34;), (
        &amp;#34;Loading of activation functions is restricted to &amp;#34;
        &amp;#34;torch.nn.modules for security reasons&amp;#34;
    )
    fn = resolve_obj_by_qualname(function_name)()
```&lt;/p&gt;
&lt;p&gt;Python&amp;#39;s `assert` statements are stripped at compile time when running in optimized mode (`python -O` or `PYTHONOPTIMIZE=1`). When the assert i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vllm&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An `assert`-based security check in vLLM&amp;#39;s activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (`python -O` or `PYTHONOPTIMIZE=1`).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;vLLM uses an `assert` statement at [`vllm/model_executor/layers/pooler/activations.py:48`](https://github.com/vllm-project/vllm/blob/main/vllm/model_executor/layers/pooler/activations.py#L48) as its sole security control to restrict which activation functions can be loaded from a HuggingFace model&amp;#39;s `config.json`:&lt;/p&gt;
&lt;p&gt;```python
# vllm/model_executor/layers/pooler/activations.py:35-53
function_name: str | None = None
if (
    hasattr(config, &amp;#34;sentence_transformers&amp;#34;)
    and &amp;#34;activation_fn&amp;#34; in config.sentence_transformers
):
    function_name = config.sentence_transformers[&amp;#34;activation_fn&amp;#34;]
elif (
    hasattr(config, &amp;#34;sbert_ce_default_activation_function&amp;#34;)
    and config.sbert_ce_default_activation_function is not None
):
    function_name = config.sbert_ce_default_activation_function&lt;/p&gt;
&lt;p&gt;if function_name is not None:
    assert function_name.startswith(&amp;#34;torch.nn.modules.&amp;#34;), (
        &amp;#34;Loading of activation functions is restricted to &amp;#34;
        &amp;#34;torch.nn.modules for security reasons&amp;#34;
    )
    fn = resolve_obj_by_qualname(function_name)()
```&lt;/p&gt;
&lt;p&gt;Python&amp;#39;s `assert` statements are stripped at compile time when running in optimized mode (`python -O` or `PYTHONOPTIMIZE=1`). When the assert i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q8gq-377p-jq3r</guid>
    </item>
  </channel>
</rss>
