Denial of Service Vulnerability in vLLM by VLLM Project
CVE-2026-105756
6.5MEDIUM
What is CVE-2026-105756?
The vLLM inference and serving engine for large language models contains a vulnerability where prior versions (before 0.30.0) allow non-empty cache_salt values to bypass character and length checks. This flaw affects deployments utilizing the LMCache-MP connector, potentially leading to an uncaught ValueError during cache lookup. Resultantly, this may cause the EngineCore to terminate unexpectedly, resulting in service denial for all concurrent users. Users are encouraged to upgrade to version 0.30.0 or later to mitigate this issue.
Affected Version(s)
vllm < 0.30.0
