CVE-2026-48746

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

criticalEPSS 1.1 %

Beschreibung

vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs). Von Version 0.3.0 bis 0.22.0 ermöglicht eine Schwachstelle in ASGI-Webservern und der Vertrauenswürdigkeit von Starlette auf diese Webserver die Umgehung der Authentifizierung des OpenAI API AuthenticationMiddleware. Dadurch kann das API ohne Bereitstellung des konfigurierten VLLM_API_KEY oder --api-key verwendet werden. Diese Schwachstelle wurde in Version 0.22.0 behoben.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.1
Quelle: nvd-v3
65.1 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.1 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-31 13:38 UTC
CWE-444

Weakness-Klassen (CWE)

  • CWE-444Base

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

    The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-01 13:19 UTC· security-advisories@github.com
    • Reference: https://github.com/vllm-project/vllm/pull/43426
    • Reference: https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6
    • Reference: https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
    • Reference: https://github.com/vllm-project/vllm/pull/43426
  2. CVE Modified2026-09-01 13:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
    • Reference: https://x41-dsec.de/lab/advisories/x41-2026-002-starlette
    • Reference Type: https://x41-dsec.de/lab/advisories/x41-2026-002-starlette Types: Third Party Advisory
  3. CVE Modified2026-09-01 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:30088
    • Reference: https://access.redhat.com/errata/RHSA-2026:30089
    • Reference: https://access.redhat.com/errata/RHSA-2026:36005
    • Reference: https://access.redhat.com/errata/RHSA-2026:36006
  4. CVE Modified2026-08-19 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+70)Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+70)
  5. CVE Modified2026-08-11 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+70)Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3 (+70)

Betroffene Betriebssysteme

  • linux

    debian / aomtrixie

  • linux

    ubuntu / ffmpegbionic

  • linux

    ubuntu / ffmpegfocal

  • linux

    ubuntu / ffmpegjammy

  • linux

    ubuntu / ffmpegnoble

  • linux

    ubuntu / ffmpegxenial

  • linux

    debian / starlettetrixie

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • anyscale

    ray2.52.0

  • bitnami

    pillow8.2.0

  • bitnami

    pillow

  • bitnami

    sqlite

  • bitnami

    thrift

  • google

    protobuf33.4

  • IBM

    Concert< 3.0.0

    gefixt in 3.0.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0.pr1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0.pr2

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.0.pr3

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.2

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.3

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.4

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.5

  • maven

    com.fasterxml.jackson.core:jackson-databind2.10.5.1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.0

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.0.rc1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.1

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.2

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.3

  • maven

    com.fasterxml.jackson.core:jackson-databind2.11.4

Quellen & Referenzen

Verknüpfte CVEs

7 weitere CVEs anzeigen

Verknüpfte Empfehlungen

IDCVE-2026-48746