Back

HIGH

vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile

Published Jun 22, 2026

Description

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the package name was not registered on PyPI, and UV_INDEX_STRATEGY="unsafe-best-match" is set globally. An attacker who registers flashinfer-jit-cache on PyPI with version 0.6.11.post2 can execute arbitrary code as root during the Docker build and backdoor every resulting container image, enabling exfiltration of all user prompts, API credentials, and model data from production vLLM deployments This vulnerability is fixed in 0.22.1.

Affected products

Remediation

Red Hat statement

CVE-2026-54232 is a build-time dependency confusion issue in upstream vLLM Dockerfiles before 0.22.1. It does not allow remote exploitation of a running vLLM inference service. Red Hat OpenShift AI is not affected. Red Hat AI Inference Server and RHEL AI CUDA images that include flashinfer-jit-cache are in scope for build-process review, but Red Hat has no evidence that shipped images were compromised. Red Hat rates this Moderate for affected products.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 22, 2026
Updated Jun 23, 2026
Reserved Jun 12, 2026
CISA Vulnrichment
Updated Jun 23, 2026
NVD
Status Analyzed
Modified Jun 24, 2026
Red Hat
Severity Moderate
Public date Jun 22, 2026
ENISA EUVD
Assigner GitHub_M
Published Jun 22, 2026
Updated Jun 23, 2026
Exploited since n/a
EUVD-2026-38405