vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile
Published Jun 22, 2026
8.8
HIGHCVSS 3.1
EPSS 0.56%
Description
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the package name was not registered on PyPI, and UV_INDEX_STRATEGY="unsafe-best-match" is set globally. An attacker who registers flashinfer-jit-cache on PyPI with version 0.6.11.post2 can execute arbitrary code as root during the Docker build and backdoor every resulting container image, enabling exfiltration of all user prompts, API credentials, and model data from production vLLM deployments This vulnerability is fixed in 0.22.1.
Affected products
-
- Version < 0.22.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vllm-Project | Vllm | n/a |
|
No data.
Red Hat AI Inference Server
rhaii/vllm-cpu-rhel9
Not affected
Red Hat AI Inference Server
rhaii/vllm-cuda-rhel9
Affected
Red Hat AI Inference Server
rhaii/vllm-gaudi-rhel9
Not affected
Red Hat AI Inference Server
rhaii/vllm-neuron-rhel9
Not affected
Red Hat AI Inference Server
rhaii/vllm-rocm-rhel9
Not affected
Red Hat AI Inference Server
rhaii/vllm-spyre-rhel9
Not affected
Red Hat AI Inference Server
rhaii/vllm-tpu-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-cpu-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-cuda-rhel9
Affected
Red Hat AI Inference Server
rhaiis/vllm-neuron-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-rocm-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-spyre-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-tpu-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-rocm-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-agent-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-controller-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-router-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-storage-initializer-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-llm-d-kv-cache-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-gaudi-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server | rhaii/vllm-cpu-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaii/vllm-cuda-rhel9 | Affected | n/a |
| Red Hat AI Inference Server | rhaii/vllm-gaudi-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaii/vllm-neuron-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaii/vllm-rocm-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaii/vllm-spyre-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaii/vllm-tpu-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-cpu-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-cuda-rhel9 | Affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-neuron-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-rocm-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-spyre-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-tpu-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-rocm-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-agent-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-controller-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-router-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-storage-initializer-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llm-d-kv-cache-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
CVE-2026-54232 is a build-time dependency confusion issue in upstream vLLM Dockerfiles before 0.22.1. It does not allow remote exploitation of a running vLLM inference service. Red Hat OpenShift AI is not affected. Red Hat AI Inference Server and RHEL AI CUDA images that include flashinfer-jit-cache are in scope for build-process review, but Red Hat has no evidence that shipped images were compromised. Red Hat rates this Moderate for affected products.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-54232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2491585 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38405 Advisory
- https://github.com/vllm-project/vllm/security/advisories/GHSA-jrf6-vqxq-pjv2 x_refsource_CONFIRMExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54232
- https://www.cve.org/CVERecord?id=CVE-2026-54232
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54232 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2491585 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38405 | Advisory | |
| https://github.com/vllm-project/vllm/security/advisories/GHSA-jrf6-vqxq-pjv2 | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54232 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54232 |
Change history (0)
No recorded changes yet.