Vulnerability in vLLM Inference Engine Affects Large Language Model Deployments
CVE-2026-105754

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105754?

The vLLM inference and serving engine for large language models contains a security vulnerability that allows attacker-controlled data inputs in the /inference/v1/generate endpoint, which can lead to various security issues including resource exhaustion, cache poisoning, and unintended alterations of transport semantics. Attackers can craft malicious inputs that exploit this flaw, especially targeting cache states and encoder behaviors. This significant issue has been addressed in vLLM version 0.30.0.

Affected Version(s)

vllm < 0.30.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.