CVE-2026-71281
Description
A flaw was found in peft. The LoRA-GA and CorDA initialization modules within Hugging Face peft improperly call torch.load() without the weights_only=True parameter. This oversight allows for full pickle deserialization when loading a malicious cache or covariance file. A remote attacker could exploit this by tricking a user into loading a specially crafted file, leading to arbitrary code execution on the affected system.
Statement
Red Hat ships Hugging Face peft (versions up to 0.19.1, all within the vulnerable range) across multiple AI/ML product images: OpenShift AI (RHOAI), the AI Inference Server (vLLM ROCm), RHEL AI, and Lightspeed Stack. The LoRA-GA and CorDA initialization modules call torch.load() on config-specified cache/covariance files without weights_only=True, enabling full pickle deserialization and arbitrary code execution if a malicious cache file is loaded. Resolution is delegated to each image's maintainers to update the pinned peft dependency; trackers have been filed against all affected streams.
Mitigation
Do not load LoRA-GA or CorDA cache/covariance files from untrusted or unverified sources; only use cache files generated in your own trusted training environment. Upgrade to a peft release newer than 0.19.1 once available in the affected image.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 8.8 | N/A | 8.8 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | Required | N/A | Required |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | High | N/A | High |
| Integrity Impact | High | N/A | High |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Integrity
Technical Impact: Modify Application Data; Unexpected State
Attackers can modify unexpected objects or data that was assumed to be safe from modification. Deserialized data or code could be modified without using the provided accessor functions, or unexpected functions could be invoked.
Availability
Technical Impact: DoS: Resource Consumption (CPU)
If a function is making an assumption on when to terminate, based on a sentry in a string, it could easily never terminate.
Other
Technical Impact: Varies by Context
The consequences can vary widely, because it depends on which objects or methods are being deserialized, and how they are used. Making an assumption that the code in the deserialized object is valid is dangerous and can enable exploitation. One example is attackers using gadget chains to perform unauthorized actions, such as generating a shell.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.