CVE-2026-71281

high Red Hat
CVSS v3 Base Score
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
High
Published: August 5, 2026 (32 days ago)
Last Modified: August 5, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in peft. The LoRA-GA and CorDA initialization modules within Hugging Face peft improperly call `torch.load()` without the `weights_only=True` parameter. This oversight allows for full pickle deserialization when loading a malicious cache or covariance file. A remote attacker could exploit this by tricking a user into loading a specially crafted file, leading to arbitrary code execution on the affected system.

CWE

CWE-502

Affected Products

Lightspeed CoreRed Hat AI Inference ServerRed Hat Enterprise Linux AI (RHEL AI) 3Red Hat OpenShift AI (RHOAI)

References