CVE-2026-24779

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)

Description

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class, specifically within the load_from_url and load_from_url_async methods. An attacker can exploit differing interpretations of backslashes by Python parsing libraries used for host restrictions to bypass these restrictions. This allows the attacker to force the vLLM server to make arbitrary requests to internal network resources, potentially leading to information disclosure, denial of service, or unauthorized access within containerized environments.

Metrics

Severity
high
no public PoC known
7.1
Source: nvd-v3
43.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-25 19:30 UTC
CWE-918

Weakness classes (CWE)

  • CWE-918Base

    Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-21 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:42644
    • Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+16)Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+16)

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_ai3.0

  • linux

    ubuntu / jqbionic

  • linux

    ubuntu / jqfocal

  • linux

    ubuntu / popplerjammy

  • linux

    ubuntu / popplernoble

  • linux

    ubuntu / popplerquesting

  • linux

    ubuntu / popplerresolute

  • other

    siemens / sinec_os

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • encode

    starlette0.8.3 – 1.0.1

  • encode

    starlette1.1.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • jqlang

    jq2026-04-12

  • libcap_project

    libcap

  • libsndfile_project

    libsndfile

  • libtiff

    libtiff

  • openbsd

    openssh10.3

  • openexr

    openexr3.1.0 – 3.2.7

  • openexr

    openexr3.3.0 – 3.3.9

  • openexr

    openexr3.4.0 – 3.4.9

  • pyasn1

    pyasn10.6.2

  • pyjwt_project

    pyjwt2.13.0

  • pypi

    vllm0.0.1

  • pypi

    vllm0.1.0

  • pypi

    vllm0.10.0

  • pypi

    vllm0.10.1

  • pypi

    vllm0.10.1.1

  • pypi

    vllm0.10.2

References & sources

Linked CVEs

IDCVE-2026-24779