CVE-2026-24049
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)
Description
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.
Metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →CWE-732Class
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-10 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/24xxx/CVE-2026-24049.json">CVE-2026-24049</a>
- CVE Modified2026-09-09 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/24xxx/CVE-2026-24049.json">CVE-2026-24049</a>
- CVE Modified2026-09-07 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/24xxx/CVE-2026-24049.json">CVE-2026-24049</a>
- CVE Modified2026-09-01 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:61628
- CVE Modified2026-08-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Discovery 2 for RHEL 10, Discovery 2 for RHEL 8, Discovery 2 for RHEL 9 (+183) → Discovery 2 for RHEL 10, Discovery 2 for RHEL 8, Discovery 2 for RHEL 9 (+183)
Affected operating systems
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
ubuntu / gdaltrusty
linux
ubuntu / gdalxenial
linux
ubuntu / golang-go.cryptobionic
linux
ubuntu / golang-go.cryptofocal
linux
ubuntu / golang-go.cryptojammy
linux
ubuntu / golang-go.cryptonoble
linux
ubuntu / golang-go.cryptoquesting
linux
ubuntu / golang-go.cryptoxenial
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
aiohttp
aiohttp3.13.3
anyscale
ray2.52.0
bitnami
golang1.24.0
bitnami
sqlite
Dell
Secure Connect GatewayAppliance 5.32.00.18
go
github.com/opencontainers/runc1.0.0-rc3
go
github.com/opencontainers/runc1.3.0-rc.1
go
github.com/opencontainers/runc1.4.0-rc.1
go
github.com/sigstore/fulcio
go
golang.org/x/oauth2
google
protobuf33.4
IBM
AIX7.2
IBM
AIX7.3
IBM
Concert< 3.0.0
fixed in 3.0.0
IBM
DevOps Code ClearCase10.0.1.05
IBM
DevOps Code ClearCase11.0.0.05
IBM
DevOps Code ClearCase9.1.0.10
IBM
MQContainer
IBM
MQOperator
IBM
TXSeriesfor multiplatforms
IBM
VIOS3.1
IBM
VIOS4.1
IGEL
OS11.11.100
IGEL
OS12.7.4
References & sources
- https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6vweb
- https://nvd.nist.gov/vuln/detail/CVE-2025-62593advisory
- https://github.com/nccgroup/singularity/pull/68web
- https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09web
- https://docs.ray.io/en/releases-2.51.1/ray-security/index.htmlweb
- https://en.wikipedia.org/wiki/Malvertisingweb
- https://github.com/ray-project/raypackage
- https://github.com/ray-project/ray/blob/e7889ae542bf0188610bc8b06d274cbf53790cbd/python/ray/dashboard/http_server_head.py#L184-L196web
- https://github.com/ray-project/ray/blob/f39a860436dca3ed5b9dfae84bd867ac10c84dc6/python/ray/dashboard/optional_utils.py#L129-L155web
- https://pypi.org/project/raypackage
- https://github.com/advisories/GHSA-q279-jhrf-cc6vadvisory
- https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysisthird-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62593government-resource
- https://github.com/vllm-project/vllm/security/advisories/GHSA-pmqf-x6x8-p7qwweb
- https://nvd.nist.gov/vuln/detail/CVE-2025-62372advisory
- https://github.com/vllm-project/vllm/pull/27204web
- https://github.com/vllm-project/vllm/pull/6613web
- https://github.com/vllm-project/vllm/commit/58fab50d82838d5014f4a14d991fdb9352c9c84bweb
- https://github.com/advisories/GHSA-pmqf-x6x8-p7qwadvisory
- https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2026-2019.yamlweb
Linked CVEs
- CVE-2026-25990
Pillow is a Python imaging library.
highCVSSv3 7.5 - CVE-2026-24779
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
highCVSSv3 7.1 - CVE-2026-24486
A flaw was found in Python-Multipart, a tool for parsing multipart form data in Python applications.
highCVSSv3 8.6 - CVE-2026-22807
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
highCVSSv3 8.8 - CVE-2026-22778
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
criticalCVSSv3 9.8 - CVE-2026-22773
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs).
mediumCVSSv3 6.5 - CVE-2026-21441
urllib3 is an HTTP client library for Python.
highCVSSv3 7.5 - CVE-2026-0994
A flaw was found in protobuf.
highCVSSv3 7.5 - CVE-2025-9900
A flaw was found in Libtiff.
highCVSSv3 8.8 - CVE-2025-9714
A flaw was found in libxstl/libxml2.
mediumCVSSv3 6.2 - CVE-2025-9230
A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap).
highCVSSv3 7.5 - CVE-2025-8176
A flaw was found in libtiff.
mediumCVSSv3 5.3 - CVE-2025-6965
A memory corruption flaw was found in SQLite.
high - CVE-2025-69223
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python.
highCVSSv3 7.5 - CVE-2025-66506
A flaw was found in Fulcio, a free-to-use certificate authority.
highCVSSv3 7.5 - CVE-2025-66471
A decompression handling flaw has been discovered in urllib3.
high - CVE-2025-66448
A remote code execution vulnerability has been identified in vLLM.
highCVSSv3 7.1 - CVE-2025-66418
A flaw was found in urllib3 Python library that could lead to a Denial of Service condition.
high - CVE-2025-62727
A denial of service vulnerability has been discovered in the python Starlette framework.
highCVSSv3 7.5 - CVE-2025-62593Actively exploited
A flaw was found in Ray’s HTTP API endpoint handling (e.g.
criticalCVSSv3 8.8 - CVE-2025-62426
A vulnerability in vLLM allows an authenticated user to trigger unintended tokenization during chat template processing by supplying craf…
mediumCVSSv3 6.5 - CVE-2025-6242
A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set.
highCVSSv3 7.1 - CVE-2025-62372
A denial-of-service vulnerability in vLLM allows an attacker with API access to crash the engine by submitting multimodal embedding tenso…
high - CVE-2025-62164
A vulnerability in vLLM allows attackers to supply malicious serialized prompt-embedding tensors that are deserialized using torch.load()…
highCVSSv3 8.8
Show 15 more CVEs
- CVE-2025-61620
A flaw was found in the server implementation of vLLM, where the handling of Jinja templates does not properly validate user-supplied inp…
— - CVE-2025-59425
A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time.
highCVSSv3 7.5 - CVE-2025-59375
A memory amplification vulnerability in libexpat allows attackers to trigger excessive dynamic memory allocations by submitting specially…
highCVSSv3 7.5 - CVE-2025-53906
A path traversal flaw was found in Vim.
mediumCVSSv3 4.1 - CVE-2025-53905
A path traversal flaw was found in Vim.
mediumCVSSv3 4.1 - CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2.
mediumCVSSv3 5.4 - CVE-2025-52565
A flaw was found in runc.
high - CVE-2025-47906
A path handling flaw has been discovered in the os/exec go package.
— - CVE-2025-22869
A flaw was found in the golang.org/x/crypto/ssh package.
— - CVE-2025-22868
A flaw was found in the `golang.org/x/oauth2/jws` package in the token parsing component.
— - CVE-2025-15467
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer…
highCVSSv3 8.8 - CVE-2024-56433
A flaw was found in shadow-utils.
lowCVSSv3 3.6 - CVE-2023-52356
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API.
highCVSSv3 7.5 - CVE-2023-52355
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API.
highCVSSv3 7.5 - CVE-2023-48022
A flaw was found in ray.
criticalCVSSv3 9.8