Deserialization of Untrusted Data Affecting vllm-openai-cuda-12.9 package, versions <0.19.1-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.35% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-VLLMOPENAICUDA129-16104672
  • published19 Apr 2026
  • disclosed7 Apr 2026

Introduced: 7 Apr 2026

CVE-2026-1839  (opens in a new tab)
CWE-502  (opens in a new tab)

How to fix?

Upgrade Chainguard vllm-openai-cuda-12.9 to version 0.19.1-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream vllm-openai-cuda-12.9 package and not the vllm-openai-cuda-12.9 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

A vulnerability in the HuggingFace Transformers library, specifically in the Trainer class, allows for arbitrary code execution. The _load_rng_state() method in src/transformers/trainer.py at line 3059 calls torch.load() without the weights_only=True parameter. This issue affects all versions of the library supporting torch&gt;=2.2 when used with PyTorch versions below 2.6, as the safe_globals() context manager provides no protection in these versions. An attacker can exploit this vulnerability by supplying a malicious checkpoint file, such as rng_state.pth, which can execute arbitrary code when loaded. The issue is resolved in version v5.0.0rc3.

CVSS Base Scores

version 3.1