CVE-2026-41523Disclosure(vllm / vllm)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vllm vllm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-617

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-22); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-22: 2Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-22: 2Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 106-2206-2306-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-222
Disclosure2
2026-06-231
Patch1
2026-06-241
Disclosure1
Full discourse4 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-41523 — vLLM The vulnerability can allow code execution when malicious Hugging Face models are loaded while Python optimised mode is enabled. Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-22/TIER_2_CVE-2026-41523.md #CyberSecurity #AIsecurity #VulnerabilityManagement #CyberObs

    Post summary

    The report describes CVE-2026-41523 in vLLM as a code‑execution flaw triggered by malicious Hugging Face models in Python's optimized mode, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000043
    55 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-41523 (CVSS 7.5) - vLLM inference engine vulnerable to RCE via malicious HuggingFace models when running in Python optimized mode. Patch to v0.22.0 immediately. #CVE #Vulnerability #PatchNow https://t.co/Q72wgpKSKF

    Post summary

    High‑severity RCE vulnerability in vLLM inference engine; immediate patch to v0.22.0 is recommended.

    0000050
    50 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41523 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows… https://www.cve.org/CVERecord?id=CVE-2026-41523 ----- Traducción: CVE-2026-41523 vLL… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-41523, noting an assert-based security flaw in vLLM prior to version 0.22.0, but does not provide a PoC, exploit, or patch details.

    0000033
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41523 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows… https://www.cve.org/CVERecord?id=CVE-2026-41523

    Post summary

    The CVE-2026-41523 entry reports a security flaw in vLLM’s activation function loading before version 0.22.0, with technical details but no PoC, patch, or evidence of exploitation.

    00000744
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more