CVE-2026-54232Disclosure(vllm / vllm)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vllm vllm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the package name was not registered on PyPI, and UV_INDEX_STRATEGY="unsafe-best-match" is set globally. An attacker who registers flashinfer-jit-cache on PyPI with version 0.6.11.post2 can execute arbitrary code as root during the Docker build and backdoor every resulting container image, enabling exfiltration of all user prompts, API credentials, and model data from production vLLM deployments This vulnerability is fixed in 0.22.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vllm

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
vllm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-22: 2Mentions · 2026-06-23: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-22: 2Technical Details · 2026-06-23: 106-2206-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-222
Disclosure2
2026-06-231
Disclosure1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-54232 (CVSS 8.8) - vLLM Docker dependency confusion flaw allows arbitrary code execution as root. Affects versions <0.22.1. Attackers can backdoor containers & exfiltrate prompts/credentials. Patch now! #CVE #Vulnerability #PatchNow https://t.co/BZeAscebYk

    Post summary

    The tweet announces a new high‑severity RCE flaw in vLLM Docker dependencies, urges users to apply the available patch, and summarizes the technical impact.

    0000055
    50 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54232 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through … https://www.cve.org/CVERecord?id=CVE-2026-54232 ----- Traducción: CVE-2026-54232 vLL… http://infoflow.cloud`

    Post summary

    The tweet reports a dependency confusion vulnerability in vLLM’s Dockerfile (before 0.22.1) as CVE-2026-54232, but offers no PoC, exploit, patch, or active exploitation details.

    0000036
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54232 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through … https://www.cve.org/CVERecord?id=CVE-2026-54232

    Post summary

    A dependency confusion vulnerability has been disclosed for vLLM’s Dockerfile prior to version 0.22.1, with no PoC, exploit, or patch details provided.

    00000733
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvllmvllm---

Explore more