Denial of Service Vulnerability in vLLM by VLLM Project
CVE-2026-105756

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105756?

The vLLM inference and serving engine for large language models contains a vulnerability where prior versions (before 0.30.0) allow non-empty cache_salt values to bypass character and length checks. This flaw affects deployments utilizing the LMCache-MP connector, potentially leading to an uncaught ValueError during cache lookup. Resultantly, this may cause the EngineCore to terminate unexpectedly, resulting in service denial for all concurrent users. Users are encouraged to upgrade to version 0.30.0 or later to mitigate this issue.

Affected Version(s)

vllm < 0.30.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.