CVE-2026-47155
Last modified
CVE-2026-47155 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vllm | Vllm | < 0.22.0 |
References
- https://github.com/vllm-project/vllm/pull/42616Issue Tracking
- https://github.com/vllm-project/vllm/security/advisories/GHSA-3ww4-5jv9-j5gmThird Party Advisory
- https://huntr.com/bounties/3f1e24c0-87d2-4f6c-a705-820f380879acThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-47155?
How severe is CVE-2026-47155?
How do I fix CVE-2026-47155?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4715Uninitialized memory in the Graphics: Canvas2D component. Th…9.1
- CVE-2026-47150In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollme…7.1
- CVE-2026-47151In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySched…7.1
- CVE-2026-47152In EmberZNet v9.0.2 and earlier, a malformed Level Control M…6.5
- CVE-2026-47153In EmberZNet v9.0.2 and earlier, a malformed Level Control S…6.5
- CVE-2026-47154In EmberZNet v9.0.2 and earlier, a malformed GetProfileRespo…6.5
- CVE-2026-47157aiograpi is an asynchronous Instagram API for Python. aiogra…6.5
- CVE-2026-47158Vaultwarden is a Bitwarden-compatible server written in Rust…8.3
- CVE-2026-47159Vaultwarden is a Bitwarden-compatible server written in Rust…6.9
- CVE-2026-4716Incorrect boundary conditions, uninitialized memory in the J…9.1
- CVE-2026-47160Vaultwarden is a Bitwarden-compatible server written in Rust…5.8
- CVE-2026-47161RELATE is a web-based courseware package. Prior to commit d6…8.7
Are you affected by CVE-2026-47155?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
