Late-Interaction Scoring Vulnerability in vLLM by the vLLM Project
CVE-2026-105755

4.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105755?

The vulnerability in vLLM arises from improper handling of the X-Request-Id header, which allows attackers to manipulate query_key values. This manipulation can corrupt cached query embeddings, causing a victim's documents to be incorrectly scored against the attacker's query. Affected users may experience unexpected behavior due to shared use counters leading to cache-miss errors. This issue is resolved in version 0.30.0 of vLLM.

Affected Version(s)

vllm < 030.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.