PT-2026-99324 · Vllm · Vllm

·

CVE-2026-100653

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions 0.22.1 through 0.27.9
Description A supply-chain integrity and reproducibility issue exists where the model revision pin provided via --revision or --code-revision is not propagated to specific Hugging Face artifact loads for FunAudioChat and Tarsier2 architectures. Specifically, this affects the WhisperFeatureExtractor and speech tokenizer PreTrainedTokenizerFast loads in vllm/model executor/models/funaudiochat.py, as well as the Qwen2VLConfig.from pretrained() function used by Tarsier2ProcessingInfo in vllm/model executor/models/qwen2 vl.py. Consequently, deployments pinned to a specific revision may still load processor, tokenizer, and configuration artifacts from the repository's default revision, allowing upstream changes to the default branch to alter audio preprocessing, speech tokenizer behavior, or Tarsier2 configuration without the operator's knowledge.
Recommendations Update vLLM to version 0.28.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100653
GHSA-HHV2-872H-628Q

Affected Products

Vllm