Vulnerability in vLLM Inference Engine Allows Tenant Isolation Bypass
CVE-2026-105752

3.1LOW

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105752?

The vLLM inference engine is vulnerable to an insecure cache management issue where prefix caching does not preserve the cache_salt value during continuation submissions. This design flaw permits an authenticated tenant to exploit cached tokens and infer whether a low-entropy post-tool history has been previously processed. Such behavior undermines the intended isolation between tenants and can lead to sensitive data leakage. The problem has been addressed in version 0.30.0, which enforces better cache handling and ensures tenant data remains secure.

Affected Version(s)

vllm < 0.30.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.