{"schema_version":1,"title":"Red Hat AI Inference Server vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Red Hat AI Inference Server: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, vLLM improper image metadata normalization in image processing, was published on 17 June 2026.","url":"https://junglewise.ai/threats/technologies/ai-inference-server","json_url":"https://junglewise.ai/threats/technologies/ai-inference-server.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ai-inference-server","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":10,"all_time":16,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":16},"latest":[{"cvss":4.8,"slug":"vllm-improper-image-metadata-normalization-in-image-processing-68504b9d","title":"vLLM improper image metadata normalization in image processing","severity":"medium","exploited":false,"published_at":"2026-06-17T18:35:47+00:00","url":"https://junglewise.ai/threats/vllm-improper-image-metadata-normalization-in-image-processing-68504b9d"},{"cve":"CVE-2026-12491","cvss":4.8,"epss":0.0024,"slug":"cve-2026-12491-vllm-improper-image-metadata-handling-in-image-processing","title":"vLLM improper image metadata handling in image processing","severity":"medium","exploited":false,"published_at":"2026-06-17T13:20:04.323+00:00","url":"https://junglewise.ai/threats/cve-2026-12491-vllm-improper-image-metadata-handling-in-image-processing"},{"cve":"CVE-2026-42561","cvss":7.5,"epss":0.0085,"slug":"cve-2026-42561-kludex-python-multipart-denial-of-service-in-multipart-header","title":"Kludex python-multipart denial of service in multipart header parsing","severity":"high","exploited":false,"published_at":"2026-05-13T21:16:47.07+00:00","url":"https://junglewise.ai/threats/cve-2026-42561-kludex-python-multipart-denial-of-service-in-multipart-header"},{"cve":"CVE-2026-41603","cvss":7.4,"epss":0.0025,"slug":"cve-2026-41603-apache-thrift-improper-certificate-validation-in-java","title":"Apache Thrift improper certificate validation in Java TSSLTransportFactory","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.113+00:00","url":"https://junglewise.ai/threats/cve-2026-41603-apache-thrift-improper-certificate-validation-in-java"},{"cve":"CVE-2026-41602","cvss":7.5,"epss":0.0138,"slug":"cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport","title":"Apache Thrift integer overflow in Go TFramedTransport","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03+00:00","url":"https://junglewise.ai/threats/cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport"},{"cve":"CVE-2026-34756","cvss":6.5,"epss":0.0077,"slug":"cve-2026-34756-vllm-denial-of-service-via-unbounded-n-parameter-in-openai-api","title":"vLLM Denial of Service via unbounded n parameter in OpenAI API server","severity":"medium","exploited":false,"published_at":"2026-04-06T16:16:36.61+00:00","url":"https://junglewise.ai/threats/cve-2026-34756-vllm-denial-of-service-via-unbounded-n-parameter-in-openai-api"},{"cve":"CVE-2026-34755","cvss":6.5,"epss":0.0084,"slug":"cve-2026-34755-vllm-denial-of-service-via-unbounded-video-frame-processing","title":"vLLM denial of service via unbounded video frame processing","severity":"medium","exploited":false,"published_at":"2026-04-06T16:16:36.463+00:00","url":"https://junglewise.ai/threats/cve-2026-34755-vllm-denial-of-service-via-unbounded-video-frame-processing"},{"cve":"CVE-2026-27893","cvss":8.8,"epss":0.0181,"slug":"cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in","title":"vLLM remote code execution via hardcoded remote code trust in models","severity":"high","exploited":false,"published_at":"2026-03-27T00:16:22.333+00:00","url":"https://junglewise.ai/threats/cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in"},{"cve":"CVE-2026-32981","cvss":7.5,"epss":0.0103,"slug":"cve-2026-32981-anyscale-ray-path-traversal-in-ray-dashboard","title":"Anyscale Ray path traversal in Ray Dashboard","severity":"high","exploited":false,"published_at":"2026-03-17T20:16:14.373+00:00","url":"https://junglewise.ai/threats/cve-2026-32981-anyscale-ray-path-traversal-in-ray-dashboard"},{"cve":"CVE-2026-28356","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28356-defnull-multipart-redos-in-parse-options-header","title":"defnull multipart ReDoS in parse_options_header","severity":"high","exploited":false,"published_at":"2026-03-12T17:16:50.08+00:00","url":"https://junglewise.ai/threats/cve-2026-28356-defnull-multipart-redos-in-parse-options-header"},{"cve":"CVE-2026-23868","cvss":5.1,"epss":0.0011,"slug":"cve-2026-23868-giflib-double-free-in-gifmakesavedimage","title":"Giflib double free in GifMakeSavedImage","severity":"medium","exploited":false,"published_at":"2026-03-10T20:16:25.517+00:00","url":"https://junglewise.ai/threats/cve-2026-23868-giflib-double-free-in-gifmakesavedimage"},{"cve":"CVE-2026-25048","cvss":7.5,"epss":0.0071,"slug":"cve-2026-25048-mlc-ai-xgrammar-uncontrolled-recursion-in-nested-syntax","title":"mlc-ai xgrammar uncontrolled recursion in nested syntax","severity":"high","exploited":false,"published_at":"2026-03-05T16:16:15.853+00:00","url":"https://junglewise.ai/threats/cve-2026-25048-mlc-ai-xgrammar-uncontrolled-recursion-in-nested-syntax"},{"cve":"CVE-2025-14831","cvss":5.3,"epss":0.0006,"slug":"cve-2025-14831-gnutls-denial-of-service-via-excessive-resource-consumption","title":"GnuTLS denial of service via excessive resource consumption during certificate verification","severity":"medium","exploited":false,"published_at":"2026-02-09T15:16:09.937+00:00","url":"https://junglewise.ai/threats/cve-2025-14831-gnutls-denial-of-service-via-excessive-resource-consumption"},{"cve":"CVE-2026-24779","cvss":7.1,"epss":0.0059,"slug":"cve-2026-24779-vllm-ssrf-in-mediaconnector-via-url-parsing-discrepancy","title":"vLLM SSRF in MediaConnector via URL parsing discrepancy","severity":"high","exploited":false,"published_at":"2026-01-27T22:15:57.28+00:00","url":"https://junglewise.ai/threats/cve-2026-24779-vllm-ssrf-in-mediaconnector-via-url-parsing-discrepancy"},{"cve":"CVE-2026-1260","cvss":7.8,"epss":0.0018,"slug":"cve-2026-1260-google-sentencepiece-heap-overflow-via-malicious-model-file","title":"Google Sentencepiece heap overflow via malicious model file","severity":"high","exploited":false,"published_at":"2026-01-22T17:16:30.643+00:00","url":"https://junglewise.ai/threats/cve-2026-1260-google-sentencepiece-heap-overflow-via-malicious-model-file"},{"cve":"CVE-2026-22807","cvss":8.8,"epss":0.0083,"slug":"cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading","title":"vLLM arbitrary code execution via auto_map dynamic module loading","severity":"high","exploited":false,"published_at":"2026-01-21T22:15:49.077+00:00","url":"https://junglewise.ai/threats/cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"},{"name":"Red Hat Enterprise Linux 9.0","slug":"enterprise-linux-9-0","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9-0"}],"technology":{"hub":true,"name":"Red Hat AI Inference Server","slug":"ai-inference-server","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"software","homepage":"https://www.redhat.com/en/technologies/cloud-computing/openshift/openshift-ai","repo_url":"https://github.com/opendatahub-io/ai-inference-server","description":"A Red Hat software component designed to serve machine learning models for inference tasks.","url":"https://junglewise.ai/threats/technologies/ai-inference-server"},"most_severe":[{"cve":"CVE-2026-27893","cvss":8.8,"epss":0.0181,"slug":"cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in","title":"vLLM remote code execution via hardcoded remote code trust in models","severity":"high","exploited":false,"published_at":"2026-03-27T00:16:22.333+00:00","url":"https://junglewise.ai/threats/cve-2026-27893-vllm-remote-code-execution-via-hardcoded-remote-code-trust-in"},{"cve":"CVE-2026-22807","cvss":8.8,"epss":0.0083,"slug":"cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading","title":"vLLM arbitrary code execution via auto_map dynamic module loading","severity":"high","exploited":false,"published_at":"2026-01-21T22:15:49.077+00:00","url":"https://junglewise.ai/threats/cve-2026-22807-vllm-arbitrary-code-execution-via-auto-map-dynamic-module-loading"},{"cve":"CVE-2026-1260","cvss":7.8,"epss":0.0018,"slug":"cve-2026-1260-google-sentencepiece-heap-overflow-via-malicious-model-file","title":"Google Sentencepiece heap overflow via malicious model file","severity":"high","exploited":false,"published_at":"2026-01-22T17:16:30.643+00:00","url":"https://junglewise.ai/threats/cve-2026-1260-google-sentencepiece-heap-overflow-via-malicious-model-file"},{"cve":"CVE-2026-41602","cvss":7.5,"epss":0.0138,"slug":"cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport","title":"Apache Thrift integer overflow in Go TFramedTransport","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03+00:00","url":"https://junglewise.ai/threats/cve-2026-41602-apache-thrift-integer-overflow-in-go-tframedtransport"},{"cve":"CVE-2026-32981","cvss":7.5,"epss":0.0103,"slug":"cve-2026-32981-anyscale-ray-path-traversal-in-ray-dashboard","title":"Anyscale Ray path traversal in Ray Dashboard","severity":"high","exploited":false,"published_at":"2026-03-17T20:16:14.373+00:00","url":"https://junglewise.ai/threats/cve-2026-32981-anyscale-ray-path-traversal-in-ray-dashboard"},{"cve":"CVE-2026-28356","cvss":7.5,"epss":0.0103,"slug":"cve-2026-28356-defnull-multipart-redos-in-parse-options-header","title":"defnull multipart ReDoS in parse_options_header","severity":"high","exploited":false,"published_at":"2026-03-12T17:16:50.08+00:00","url":"https://junglewise.ai/threats/cve-2026-28356-defnull-multipart-redos-in-parse-options-header"},{"cve":"CVE-2026-42561","cvss":7.5,"epss":0.0085,"slug":"cve-2026-42561-kludex-python-multipart-denial-of-service-in-multipart-header","title":"Kludex python-multipart denial of service in multipart header parsing","severity":"high","exploited":false,"published_at":"2026-05-13T21:16:47.07+00:00","url":"https://junglewise.ai/threats/cve-2026-42561-kludex-python-multipart-denial-of-service-in-multipart-header"},{"cve":"CVE-2026-25048","cvss":7.5,"epss":0.0071,"slug":"cve-2026-25048-mlc-ai-xgrammar-uncontrolled-recursion-in-nested-syntax","title":"mlc-ai xgrammar uncontrolled recursion in nested syntax","severity":"high","exploited":false,"published_at":"2026-03-05T16:16:15.853+00:00","url":"https://junglewise.ai/threats/cve-2026-25048-mlc-ai-xgrammar-uncontrolled-recursion-in-nested-syntax"},{"cve":"CVE-2026-41603","cvss":7.4,"epss":0.0025,"slug":"cve-2026-41603-apache-thrift-improper-certificate-validation-in-java","title":"Apache Thrift improper certificate validation in Java TSSLTransportFactory","severity":"high","exploited":false,"published_at":"2026-04-28T10:16:03.113+00:00","url":"https://junglewise.ai/threats/cve-2026-41603-apache-thrift-improper-certificate-validation-in-java"},{"cve":"CVE-2026-24779","cvss":7.1,"epss":0.0059,"slug":"cve-2026-24779-vllm-ssrf-in-mediaconnector-via-url-parsing-discrepancy","title":"vLLM SSRF in MediaConnector via URL parsing discrepancy","severity":"high","exploited":false,"published_at":"2026-01-27T22:15:57.28+00:00","url":"https://junglewise.ai/threats/cve-2026-24779-vllm-ssrf-in-mediaconnector-via-url-parsing-discrepancy"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}