{"data":{"id":"25987ef1-f8ba-4046-bae3-6945afff7ef7","title":"CVE-2026-100653: vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-","summary":"vLLM (an engine for running large language models) versions 0.22.1 through 0.28.0 have a bug where certain model settings are not applied correctly for two specific model types (FunAudioChat and Tarsier2). When operators pin their deployments to a specific version for safety, the system still pulls some components (tokenizers and configs, which control how audio is processed) from the default upstream version instead, meaning unexpected changes to the base repository could alter how the model behaves without the operator knowing.","solution":"The issue is fixed in version 0.28.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100653","publishedAt":"2026-09-26T14:16:47.953Z","cveId":"CVE-2026-100653","cweIds":["CWE-348"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["vLLM","HuggingFace","FunAudioChat","Tarsier2","Qwen2VL"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.953Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}