RHSA-2026:57390HighCVSS 7.5

Red Hat Security Advisory: Red Hat AI Inference 3.4.4 (rocm)

Published
August 20, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-34753 — vllm: vLLM: Server-Side Request Forgery allows access to internal services via controlled batch input CVE-2026-34755 — vLLM: vLLM: Denial of Service due to excessive video frame processing CVE-2026-34756 — vllm: vLLM: Denial of Service via excessively large 'n' parameter in OpenAI-compatible API CVE-2026-41523 — vllm: vLLM: Arbitrary code execution via malicious HuggingFace model CVE-2026-44223 — vllm: vLLM: Denial of Service via malformed tensor shape in speculative decoding

🎯 Affected products2

  • Red Hat AI Inference Server 3.4
  • registry.redhat.io/rhaii/vllm-rocm-rhel9@sha256:eb2ca896461f782d8c4c239d36545a1a749d17bebd9fdc0652024092614c69c2_amd64 as a component of Red Hat AI Inference Server 3.4

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:57390 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (9)