RHSA-2026:59138HighCVSS 7.5

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.6 (CUDA)

Published
August 24, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-41523 — vllm: vLLM: Arbitrary code execution via malicious HuggingFace model CVE-2026-47155 — vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls CVE-2026-53923 — vllm: vLLM: Information disclosure via integer truncation

🎯 Affected products3

  • Red Hat AI Inference Server 3.3
  • registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:201b9f3ebdbaa9979d9f40276e3aa5cc78f20d08ed3abae90954caff30ae9d8b_arm64 as a component of Red Hat AI Inference Server 3.3
  • registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:333f2a87d0dd8bc399eb7c1d9c7033e2c90c25c1b1b44a9941f16437b33ddccb_amd64 as a component of Red Hat AI Inference Server 3.3

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:59138 Workaround: Avoid running vLLM with python -O or PYTHONOPTIMIZE=1 until updated packages are available. Only load models from trusted sources. Restrict who can deploy or update models on inference endpoints. Apply network access controls and authentication in front of vLLM APIs. Workaround: Upgrade to a vLLM build containing the fix (>= 0.22.0) when available from Red Hat. Until then, only serve models from trusted registries, pin revisions explicitly, and review nested artifacts in model repositories before deployment. Workaround: No mitigation is required for unaffected deployments. Restrict untrusted access to inference APIs as a general hardening measure.

🔗 References (7)