CVE-2026-22807
Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)
Description
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). This vulnerability allows a remote attacker to achieve arbitrary code execution on the vLLM host during model loading. This occurs because vLLM loads Hugging Face `auto_map` dynamic modules without properly validating the `trust_remote_code` setting. By influencing the model repository or path, an attacker can execute malicious Python code at server startup, even before any API requests are handled.
Metrics
Weakness classes (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-21 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:42644
- Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+17) → Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+17)
Affected operating systems
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_ai3.0
linux
ubuntu / jqbionic
linux
ubuntu / jqfocal
linux
ubuntu / popplerjammy
linux
ubuntu / popplernoble
linux
ubuntu / popplerquesting
linux
ubuntu / popplerresolute
other
siemens / sinec_os
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
python-min3.11.0
bitnami
python-min3.12.0
bitnami
python-min3.13.0
bitnami
python-min3.14.0
cryptography.io
cryptography45.0.0 – 46.0.7
encode
starlette0.8.3 – 1.0.1
encode
starlette1.1.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
jqlang
jq2026-04-12
libcap_project
libcap
libsndfile_project
libsndfile
libtiff
libtiff
openbsd
openssh10.3
openexr
openexr3.1.0 – 3.2.7
openexr
openexr3.3.0 – 3.3.9
openexr
openexr3.4.0 – 3.4.9
pyasn1
pyasn10.6.2
pyjwt_project
pyjwt2.13.0
pypi
vllm0.0.1
pypi
vllm0.1.0
pypi
vllm0.10.0
pypi
vllm0.10.1
pypi
vllm0.10.1.1
pypi
vllm0.10.2
References & sources
- https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9x_refsource_CONFIRM
- https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615x_refsource_MISC
- https://github.com/vim/vim/releases/tag/v9.2.0276x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2026/04/01/1
- https://access.redhat.com/security/cve/CVE-2026-34982vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2455400issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:30900vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:11389vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19073vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:11509vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:33453vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34477vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34476vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28133vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28049vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28050vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:11510vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19224vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36004vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-6100
A flaw was found in Python's decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`.
criticalCVSSv3 8.1 - CVE-2026-48818
A flaw was found in Starlette, a lightweight ASGI framework.
highCVSSv3 7.5 - CVE-2026-4878
A flaw was found in libcap.
highCVSSv3 7.0 - CVE-2026-48746
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
criticalCVSSv3 9.1 - CVE-2026-48710Actively exploited
A flaw was found in Starlette, a lightweight ASGI (Asynchronous Server Gateway Interface) framework.
criticalCVSSv3 6.5 - CVE-2026-48526
A flaw was found in PyJWT, a Python library for JSON Web Token (JWT) implementation.
highCVSSv3 7.4 - CVE-2026-4786
A flaw was found in the Python webbrowser.open() API.
highCVSSv3 7.1 - CVE-2026-4775
A flaw was found in the libtiff library.
highCVSSv3 7.8 - CVE-2026-44432
urllib3 is an HTTP client library for Python.
highCVSSv3 7.5 - CVE-2026-44431
A flaw was found in urllib3, an HTTP client library for Python.
high - CVE-2026-40164
A flaw was found in jq, a command-line JSON processor.
highCVSSv3 7.5 - CVE-2026-39979
A flaw was found in jq, a command line JSON processor, specifically in the libjq API.
mediumCVSSv3 6.5 - CVE-2026-39892
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.
criticalCVSSv3 9.8 - CVE-2026-37555
A flaw was found in the libsndfile library.
highCVSSv3 7.5 - CVE-2026-35535
A flaw was found in Sudo.
highCVSSv3 7.8 - CVE-2026-35385
A flaw was found in OpenSSH.
highCVSSv3 8.1 - CVE-2026-34982
A flaw was found in Vim.
highCVSSv3 8.2 - CVE-2026-34588
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture in…
highCVSSv3 7.8 - CVE-2026-24779
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
highCVSSv3 7.1 - CVE-2026-23490
A flaw was found in pyasn1, a generic ASN.1 library for Python.
highCVSSv3 7.5 - CVE-2026-22778
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
criticalCVSSv3 9.8 - CVE-2026-10118
A flaw was found in Poppler's Splash backend.
highCVSSv3 7.8