Denial-of-Service Vulnerability in vLLM by vLLM Project
CVE-2026-100647
6.9MEDIUM
What is CVE-2026-100647?
vLLM versions prior to 0.29.0 are vulnerable to a denial-of-service attack through the cache_salt parameter on OpenAI-compatible and Anthropic API endpoints. This vulnerability allows unauthenticated attackers to send HTTP requests with excessively large salt values. The absence of maximum length validation results in expensive operations involving pickle serialization and SHA-256 hashing, which monopolize the EngineCore scheduler thread. Consequently, this leads to significant performance degradation, hindering the ability to process concurrent requests and resulting in denial of service.
Affected Version(s)
vllm 0 < 0.29.0
vllm 0.29.0
