vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLMs revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies –revision or –code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Vllm | Vllm | * | 0.22.0 (excluding) |
| Red Hat AI Inference Server 3.3 | RedHat | rhaiis/vllm-cuda-rhel9:1787161382 | * |
| Red Hat AI Inference Server 3.3 | RedHat | rhaiis/vllm-rocm-rhel9:1787161803 | * |
| Red Hat AI Inference Server 3.3 | RedHat | rhaiis/vllm-spyre-rhel9:1787161776 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/disk-image-cuda-rhel9:1788290314 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/bootc-aws-cuda-rhel9:1788273908 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/bootc-azure-cuda-rhel9:1788273909 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/bootc-azure-rocm-rhel9:1788273908 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/bootc-cuda-rhel9:1788260684 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/bootc-gcp-cuda-rhel9:1788273977 | * |
| Red Hat Enterprise Linux AI 3.3 | RedHat | rhelai3/bootc-rocm-rhel9:1788260620 | * |