Vllm · Vllm · CVE-2026-105756
**Name of the Vulnerable Software and Affected Versions**
vLLM versions prior to 0.30.0
**Description**
vLLM is an inference and serving engine for large language models. OpenAI-compatible request models accept a `cache salt` value without enforcing the character and length restrictions required by the `IPCCacheServerKey` consumer in LMCache-MP. On deployments using the LMCache-MP connector, a salt that contains forbidden characters (such as `@`, `/`, ``, or NUL) or exceeds 128 characters can trigger an uncaught `ValueError` during scheduler cache lookup. Because the `Scheduler.schedule()` function does not wrap this call in a request-scoped exception handler, the error propagates to the `EngineCore` top-level handler, which treats any uncaught exception as fatal and terminates the entire engine process. This results in a denial of service for all concurrent users. The issue is triggered via the `cache salt` variable in request models including Completions, Chat Completions, and Responses.
**Recommendations**
Update vLLM to version 0.30.0 or later.
As a temporary mitigation, avoid using the `cache salt` parameter in requests or ensure it does not contain the characters `@`, `/`, ``, or NUL and does not exceed 128 characters.