Late-Interaction Scoring Vulnerability in vLLM by the vLLM Project
CVE-2026-105755
4.2MEDIUM
What is CVE-2026-105755?
The vulnerability in vLLM arises from improper handling of the X-Request-Id header, which allows attackers to manipulate query_key values. This manipulation can corrupt cached query embeddings, causing a victim's documents to be incorrectly scored against the attacker's query. Affected users may experience unexpected behavior due to shared use counters leading to cache-miss errors. This issue is resolved in version 0.30.0 of vLLM.
Affected Version(s)
vllm < 030.0
