Threats Tagged 'cve-2026-47155'
View all threats tagged with 'cve-2026-47155'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-47155'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat® Enterprise Linux® AI is a foundation model platform to seamlessly develop, test, and run Granite family large language models (LLMs) for enterprise applications. This update provides the latest Red Hat Enterprise Linux AI 3.3.6 container images. For a full list of changes in this release, see the Red Hat Enterprise Linux AI Release Notes linked in the References section. Join the discussion | GCVE Database | 09/01/2026, 21:55:16 UTC Added: 08/31/2026, 15:42:17 UTC |
CVE-2026-44222 is a denial of service vulnerability in vLLM, an inference engine for large language models, as integrated into Red Hat AI Inference Server 3.3.6 (Spyre). Unauthenticated attackers can cause worker termination by submitting malformed multimodal inputs or text prompts with special tokens, disrupting AI inference workloads. No fix is currently available that meets Red Hat's criteria for deployment and stability. Join the discussion | GCVE Database | 08/26/2026, 16:25:47 UTC Added: 08/31/2026, 15:42:17 UTC |
A vulnerability in vLLM, the inference and serving engine used by Red Hat AI Inference Server, allows an unauthenticated attacker to achieve arbitrary code execution by loading a malicious HuggingFace model while vLLM runs in Python optimized mode. This affects Red Hat AI Inference Server versions prior to 0.22.0 that include the vulnerable pooler activation loader. Exploitation requires the attacker to supply an untrusted model and the server to be running with Python optimization enabled. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for RHEL AI bootc images bundling vLLM. No fix is currently available. Mitigations include avoiding running vLLM with Python optimization, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls. Join the discussion | GCVE Database | 08/24/2026, 16:51:58 UTC Added: 08/25/2026, 13:38:33 UTC |
A vulnerability in Red Hat AI Inference Server 3.3.6 (CUDA) involves an assert-based security check flaw in the vLLM inference engine for large language models. An unauthenticated attacker can exploit this by publishing a malicious HuggingFace model, potentially achieving arbitrary code execution when vLLM runs in Python optimized mode. The issue affects Red Hat AI Inference Server 3.3 images with vLLM versions prior to 0.14.0. Red Hat rates the impact as Important for AI Inference Server and OpenShift AI vLLM serving images, and Moderate for bundled vLLM in Enterprise Linux AI bootc images. No fix is currently available. Mitigations include avoiding running vLLM with Python optimization flags, loading models only from trusted sources, restricting model deployment permissions, and applying network access controls. Join the discussion | GCVE Database | 08/24/2026, 16:51:10 UTC Added: 08/25/2026, 13:38:33 UTC |
0 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0. Join the discussion | CVE Database V5 | 06/22/2026, 22:20:10 UTC Added: 06/22/2026, 22:39:45 UTC |
Showing 1 to 5 of 5 results