RHSA-2026:60363HighCVSS 7.5

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.6 (Spyre)

Published
August 26, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-44222 — vllm: vLLM: Denial of Service via malformed multimodal input or token injection CVE-2026-47155 — vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls CVE-2026-53923 — vllm: vLLM: Information disclosure via integer truncation CVE-2026-54234 — vllm: vLLM: Denial of Service via malformed speculative decoding workload CVE-2026-55574 — vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API

🎯 Affected products4

  • Red Hat AI Inference Server 3.3
  • registry.redhat.io/rhaiis/vllm-spyre-rhel9@sha256:590f1bb37f9c9abb51a6ff7f557b45f1dcfba2e4880de979290703c2e6de95be_s390x as a component of Red Hat AI Inference Server 3.3
  • registry.redhat.io/rhaiis/vllm-spyre-rhel9@sha256:e54618292d1e6f1c9c959a42160bad3a153ca7e050665739d3ddd9dbfda541f8_ppc64le as a component of Red Hat AI Inference Server 3.3
  • registry.redhat.io/rhaiis/vllm-spyre-rhel9@sha256:f3dfb688e524f44f071f20954e454a91013a9c48f8cc59a32f7f402bb61d8ed0_amd64 as a component of Red Hat AI Inference Server 3.3

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:60363 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a vLLM build containing the fix (>= 0.22.0) when available from Red Hat. Until then, only serve models from trusted registries, pin revisions explicitly, and review nested artifacts in model repositories before deployment. Workaround: No mitigation is required for unaffected deployments. Restrict untrusted access to inference APIs as a general hardening measure. Workaround: To mitigate this issue, restrict network access to the vLLM inference engine's gRPC Generate and Abort endpoints. Configure firewall rules to limit incoming connections to trusted clients or internal networks only. This will prevent remote, unauthenticated attackers from sending malformed workloads and triggering a denial of service. If the service is exposed via a proxy or load balancer, ensure that access controls are in place at that layer.

🔗 References (9)