Use of Incorrectly-Resolved Name or Reference Affecting vllm package, versions [,0.22.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-VLLM-17304846
  • published11 Jun 2026
  • disclosed10 Jun 2026
  • creditaddcontent

Introduced: 10 Jun 2026

NewCVE-2026-47155  (opens in a new tab)
CWE-706  (opens in a new tab)

How to fix?

Upgrade vllm to version 0.22.0 or higher.

Overview

vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs

Affected versions of this package are vulnerable to Use of Incorrectly-Resolved Name or Reference through several model loading paths. An attacker can make the server load a different Hugging Face artifact than intended by supplying a model reference that is fetched without the requested revision, or by triggering secondary artifact loads that omit the pinned revision or code revision. This can cause the user to run or serve the wrong model weights and associated remote code, leading to model integrity loss and exposure to attacker-controlled model behavior.

CVSS Base Scores

version 4.0
version 3.1