Red Hat Security Advisory: Red Hat AI Inference Server 3.3.6 (CUDA)
Description
A vulnerability in Red Hat AI Inference Server 3.3.6 (CUDA) involves an assert-based security check flaw in the vLLM inference engine used for large language models. An unauthenticated attacker can exploit this by publishing a malicious HuggingFace model, potentially leading to arbitrary code execution when vLLM runs in Python optimized mode. The issue affects Red Hat AI Inference Server versions from 3.2 up to but not including 3.4. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for bundled vLLM in Enterprise Linux AI bootc images. No official fix is currently available. Mitigations include avoiding running vLLM with Python optimization flags, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-41523 affects Red Hat AI Inference Server 3.3.6 (CUDA) and involves an assert-based security check flaw in the vLLM inference engine for large language models. This flaw allows an unauthenticated attacker to publish a malicious HuggingFace model that, when loaded by vLLM running in Python optimized mode, can lead to arbitrary code execution. The affected versions include Red Hat AI Inference Server images from version 3.2 up to but not including 3.4. Red Hat classifies the severity as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for the bundled vLLM in Enterprise Linux AI bootc images. Currently, no patch or official fix is available. Recommended mitigations are to avoid running vLLM with Python optimization flags, only load models from trusted sources, restrict permissions for model deployment, and enforce network access controls to limit exposure.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to achieve arbitrary code execution on systems running vulnerable versions of Red Hat AI Inference Server with vLLM in Python optimized mode. This could potentially allow the attacker to execute malicious code remotely by publishing a crafted malicious model. The impact severity is rated as Important (high) for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for bundled vLLM in Enterprise Linux AI bootc images.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Red Hat recommends the following mitigations: avoid running vLLM with Python optimization flags; only load models from trusted sources such as verified HuggingFace repositories; restrict permissions for model deployment to trusted users; and apply network access controls to limit exposure of the AI Inference Server. These mitigations reduce the risk of exploitation until a patch is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:59138
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-47155","CVE-2026-53923"]
- State
- PUBLISHED
Threat ID: 6a8d9ad9acd9273b493e14b1
Added to database: 08/25/2026, 13:38:33 UTC
Last enriched: 10/06/2026, 21:52:59 UTC
Last updated: 10/09/2026, 18:48:19 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.