Junglewise Threat Intelligence

CVE-2026-54232: vLLM dependency confusion in Dockerfile via flashinfer-jit-cache

CVE-2026-54232 · Severity: high · CVSS 8.8 · Published 2026-06-22

Technologies: vllm (PyPI), vLLM Project vllm. Vendors: PyPI, vLLM Project.

Executive brief

vLLM is a popular engine used to run and serve large language models (LLMs). A security flaw in its build process allows attackers to perform a 'dependency confusion' attack, where a malicious package is substituted for a legitimate one during the creation of the software's container image. If exploited, this allows an attacker to embed a backdoor in the software, potentially leading to the theft of sensitive user prompts, API keys, and proprietary model data from any organization using the affected versions.

Technical details

A dependency confusion vulnerability exists in the vLLM Dockerfile due to the use of the `flashinfer-jit-cache` package. The build process uses `uv pip install` with `--extra-index-url` pointing to a custom repository, but the package name was not reserved on the public PyPI registry. Combined with the global setting `UV_INDEX_STRATEGY="unsafe-best-match"`, the installer may prioritize a malicious package uploaded to PyPI over the intended custom version. An attacker who registers the package on PyPI can achieve root-level remote code execution during the Docker build process. This allows for the insertion of a persistent backdoor into the final container image, enabling the exfiltration of prompts, credentials, and model weights. The issue is resolved in version 0.22.1.

Affected products

  • vllm-project vLLM < 0.22.1

Timeline

  • 2026-06-09: advisory: GitHub Security Advisory published
  • 2026-06-22: disclosed: CVE published to NVD
  • 2026-06-22: patched: Fix confirmed in version 0.22.1

References

Related threats