CVE-2026-47155
MEDIUM
6.5
CVSS 3.1
Description
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.
Metadata
Severity & Metrics
6.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| vllm-project | vllm | — | < 0.22.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-345 | cna | CWE-345: Insufficient Verification of Data Authenticity |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 6.5 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N |
References (4)
- https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gm
- https://github.com/vllm-project/vllm/pull/42616 https://github.com/vllm-project/vllm/pull/42616
- https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6 https://github.com/vllm-project/vllm/commit/d26a28ab033697f55a1414b5b0435de7cd6045b6
- https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879ac