Database/AI/ML frameworks & serving
vLLM: --revision pin ignored for some FunAudioChat and Tarsier2 processor, tokenizer and config loads
Impact
In vLLM 0.22.1 through 0.28.0 the operator's --revision / --code-revision pin is not passed to several Hugging Face artifact loads for the FunAudioChat and Tarsier2 architectures: the WhisperFeatureExtractor and speech_tokenizer PreTrainedTokenizerFast loads in funaudiochat.py, and the Qwen2VLConfig.from_pretrained call used by Tarsier2ProcessingInfo in qwen2_vl.py. A deployment pinned to a reviewed revision still resolves those behaviour-affecting artifacts from the repository's default branch, so an upstream change can alter audio preprocessing, speech tokenizer behaviour or Tarsier2 configuration on the next server start with no change to the operator's config. This is a supply-chain integrity and reproducibility failure, not remote code execution: the advisory is explicit that it is neither RCE nor a trust_remote_code=False bypass. It is residual to the earlier fix tracked as GHSA-3ww4-5jv9-j5gm / CVE-2026-47155. For a fleet serving these two architectures it means the pin that audit and reproducibility claims rest on was not actually in force.
Who can reach it
No direct attacker interaction with the serving node. Requires control of, or a change to, the default branch of the upstream Hugging Face model repository the deployment loads - i.e. the model publisher or anyone who compromises that repository. Affects only deployments serving FunAudioChat or Tarsier2.
What to do
Upgrade vLLM to 0.28.0 or later and restart the serving processes; the fix is in-tree. If you serve these architectures under a pin, also verify which processor, tokenizer and config artifacts your running servers actually loaded, since a drifted default branch may already be in effect - mirroring the model repository locally at the reviewed commit removes the dependency on upstream default-branch stability. Rolling restart of the inference deployment; no node drain.
References
Related entries
- Dagster: Vulnerability in Dagster Core prior to 1.13.1CVE-2026-41490 · DagsterHigh
- Gitingest: prefix-only host validation lets crafted URLs leak GitHub tokens to attacker hostsCVE-2026-82289 · Gitingest (_validate_host git host allowlist)High
- TorchServe (gRPC 7070/7071): gRPC ports bound to all interfaces regardless of configCVE-2024-35199 · TorchServe (gRPC 7070/7071)High
- Ollama (GGUF parser): Malformed 4-byte GGUF file crashes the server (two HTTP requests)CVE-2024-39720 · Ollama (GGUF parser)High
- vLLM: out-of-vocabulary stop_token_ids kill EngineCore and take the model server down until restartCVE-2026-100652 · vLLM (Rust HTTP/gRPC frontend, stop_token_ids validation)High
- GitLab AI Gateway: crafted model metadata redirects model requests and discloses Vertex or Bedrock credentialsCVE-2026-19889 · GitLab AI Gateway (Duo Agent Platform model metadata handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.