PT-2026-106262 · Vllm · Vllm
CVE-2026-105752
·
Published
2026-10-05
·
Updated
2026-10-06
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.30.0
Description
In vLLM, Harmony tool continuations submitted through the "POST /v1/responses" endpoint rebuild the next-turn engine input without preserving the
cache salt value. This causes the continuation prefix to be stored in the global unsalted cache namespace, even when the caller has enabled salting for tenant isolation. On deployments where prefix caching is enabled (the default setting), an authenticated tenant who can reconstruct a victim's low-entropy post-tool history can submit the same continuation and use the cached tokens per turn count to determine if the prefix was previously processed. This effectively creates a prompt-membership oracle that defeats the intended isolation of salted prefix caching.Recommendations
Update vLLM to version 0.30.0 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vllm