{
  "threat_severity" : "Moderate",
  "public_date" : "2026-04-06T15:36:52Z",
  "bugzilla" : {
    "description" : "vllm: vLLM: Server-Side Request Forgery allows access to internal services via controlled batch input",
    "id" : "2455394",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2455394"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side request forgery (SSRF) vulnerability in download_bytes_from_url allows any actor who can control batch input JSON to make the vLLM batch runner issue arbitrary HTTP/HTTPS requests from the server, without any URL validation or domain restrictions.\nThis can be used to target internal services (e.g. cloud metadata endpoints or internal HTTP APIs) reachable from the vLLM host. This vulnerability is fixed in 0.19.0.", "A flaw was found in vLLM. This server-side request forgery (SSRF) vulnerability allows an attacker who can control batch input JSON to force the vLLM batch runner to make arbitrary HTTP/HTTPS requests from the server. This can be exploited to access internal services, such as cloud metadata endpoints or internal HTTP APIs, potentially leading to information disclosure or further compromise of the host system." ],
  "affected_release" : [ {
    "product_name" : "Red Hat AI Inference Server 3.4",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57380",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.4::el9",
    "package" : "rhaii/vllm-cpu-rhel9:1787151769"
  }, {
    "product_name" : "Red Hat AI Inference Server 3.4",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57387",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.4::el9",
    "package" : "rhaii/vllm-spyre-rhel9:1787151840"
  }, {
    "product_name" : "Red Hat AI Inference Server 3.4",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57389",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.4::el9",
    "package" : "rhaii/vllm-cuda-rhel9:1787151771"
  }, {
    "product_name" : "Red Hat AI Inference Server 3.4",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57390",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.4::el9",
    "package" : "rhaii/vllm-rocm-rhel9:1787151774"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59144",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/disk-image-cuda-rhel9:1787310717"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59151",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/bootc-aws-cuda-rhel9:1787253912"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59151",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/bootc-azure-cuda-rhel9:1787253989"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59151",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/bootc-azure-rocm-rhel9:1787254059"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59151",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/bootc-cuda-rhel9:1787243961"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59151",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/bootc-gcp-cuda-rhel9:1787253774"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.4",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59151",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.4::el9",
    "package" : "rhelai3/bootc-rocm-rhel9:1787244006"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Fix deferred",
    "package_name" : "rhaiis/vllm-neuron-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Fix deferred",
    "package_name" : "rhaiis/vllm-tpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-kserve-agent-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-kserve-controller-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-kserve-router-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-kserve-storage-initializer-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-vllm-cpu-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-vllm-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-vllm-gaudi-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-vllm-rocm-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-34753\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34753\nhttps://github.com/vllm-project/vllm/security/advisories/GHSA-pf3h-qjgv-vcpr" ],
  "name" : "CVE-2026-34753",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}