Red hat ai inference server
This hub aggregates every CVE we track for Red hat ai inference server, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
24
CVEs tracked
0
Critical
14
High
0
In CISA KEV
Severity distribution
HIGH14MEDIUM9LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
3
2
0
1
1
0
2
6
1
5
2
0
1
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat ai inference server.
- CVE-2026-12491Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations4.8
- CVE-2026-40192Pillow is vulnerable to a FITS GZIP decompression bomb7.5
- CVE-2026-6385Ffmpeg: ffmpeg: denial of service and potential arbitrary code execution via signed integer overflow in dvd subtitle parser6.5
- CVE-2026-5121Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing7.5
- CVE-2026-25645Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function4.4
- CVE-2026-4519webbrowser.open() allows leading dashes in URLs3.3
- CVE-2026-4424Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing7.5
- CVE-2026-30922pyasn1 Vulnerable to Denial of Service via Unbounded Recursion7.5
- CVE-2025-13327Uv: uv: specially crafted zip archives lead to arbitrary code execution due to parsing differentials6.3
- CVE-2026-0994Denial of Service in Python Protobuf8.6
- CVE-2026-23490pyasn1 has a DoS vulnerability in decoder7.5
- CVE-2025-69228AIOHTTP vulnerable to denial of service through large payloads7.5
- CVE-2025-69227AIOHTTP vulnerable to DoS when bypassing asserts7.5
- CVE-2025-69226AIOHTTP allows for a brute-force leak of internal static filepath components5.3
- CVE-2025-69223AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb7.5
Product normalization is registry-driven with AI assist and human review. How it works