Supply Chain Integrity Issue in vLLM Deployment for Large Language Models
CVE-2026-100653

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100653?

In versions 0.22.1 to 0.28.0 of vLLM, the operator-defined model revision pin is not properly propagated across certain artifact loads for the FunAudioChat and Tarsier2 architectures. This results in deployments still using default revisions from the repository, leading to inconsistent audio processing and tokenizer behavior due to changes in the upstream default branch. While this presents a risk in reproducibility and integrity of model deployments, it does not allow for remote code execution or side-by-side trust issues. The problem has been addressed in version 0.28.0.

Affected Version(s)

vllm 0.22.1 < 0.28.0

vllm 0.28.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
jperezdealgaba
KernelClint
.