Skip to main content

Threats Tagged 'cve-2026-41523'

View all threats tagged with 'cve-2026-41523'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-41523

Threats Tagged 'cve-2026-41523'

Click on any threat for detailed analysis and mitigation recommendations

The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.

Join the discussion

Red Hat AI Inference 3.4.5 (rocm) includes multiple security vulnerabilities, including CVE-2026-34993, which affects the AIOHTTP Python framework. This vulnerability allows potential arbitrary code execution when untrusted input is loaded via the CookieJar.load() function. Exploitation requires an application to be configured to load attacker-controlled files, which is not typical in default Red Hat deployments. No official fixes are currently available for these vulnerabilities in Red Hat AI Inference 3.4.5 (rocm).

Join the discussion

Red Hat AI Inference 3.4.5 (cuda) is referenced in a security advisory listing multiple CVEs including CVE-2026-5241. The advisory does not provide specific details or fixes for CVE-2026-5241 itself. One related vulnerability, CVE-2026-34993 in the AIOHTTP Python framework, allows potential arbitrary code execution via untrusted input to the CookieJar.load() function, but exploitation requires specific application configurations. No official patch or fix is currently provided for Red Hat AI Inference 3.4.5 (cuda) regarding these vulnerabilities.

Join the discussion

A security advisory for Red Hat AI Inference 3.4.5 (cpu) addresses multiple vulnerabilities including CVE-2026-34993, which involves a flaw in the AIOHTTP Python asynchronous HTTP framework. This flaw allows potential arbitrary code execution when untrusted input is loaded via the CookieJar.load() function. Exploitation requires an application to be configured to process attacker-controlled files, which is not common in default Red Hat deployments. The advisory does not list any fixes currently available for these vulnerabilities.

Join the discussion

Red Hat® Enterprise Linux® AI is a foundation model platform to seamlessly develop, test, and run Granite family large language models (LLMs) for enterprise applications. This update provides the latest Red Hat Enterprise Linux AI 3.3.6 container images. For a full list of changes in this release, see the Red Hat Enterprise Linux AI Release Notes linked in the References section.

Join the discussion

A vulnerability in vLLM, the inference and serving engine used by Red Hat AI Inference Server, allows an unauthenticated attacker to achieve arbitrary code execution by loading a malicious HuggingFace model while vLLM runs in Python optimized mode. This affects Red Hat AI Inference Server versions prior to 0.22.0 that include the vulnerable pooler activation loader. Exploitation requires the attacker to supply an untrusted model and the server to be running with Python optimization enabled. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for RHEL AI bootc images bundling vLLM. No fix is currently available. Mitigations include avoiding running vLLM with Python optimization, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls.

Join the discussion

A vulnerability in Red Hat AI Inference Server 3.3.6 (CUDA) involves an assert-based security check flaw in the vLLM inference engine for large language models. An unauthenticated attacker can exploit this by publishing a malicious HuggingFace model, potentially achieving arbitrary code execution when vLLM runs in Python optimized mode. The issue affects Red Hat AI Inference Server 3.3 images with vLLM versions prior to 0.14.0. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for bundled vLLM in Enterprise Linux AI bootc images. No fix is currently available. Mitigations include avoiding running vLLM with Python optimization flags, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls.

Join the discussion

CVE-2026-34753 is a server-side request forgery (SSRF) vulnerability found in the vLLM component of Red Hat AI Inference Server 3.4.4. It allows an attacker who can control batch input JSON to make arbitrary HTTP/HTTPS requests from the server, potentially accessing internal services such as cloud metadata endpoints or internal HTTP APIs. No official fix or patch is currently available from Red Hat for this vulnerability. The vulnerability has a Red Hat CVSS score of 5.4 (medium severity) but is assessed here as high severity due to the potential for information disclosure and further system compromise.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: cve-2026-41523
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses