PT-2026-106262 · Vllm · Vllm

CVE-2026-105752

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.30.0
Description In vLLM, Harmony tool continuations submitted through the "POST /v1/responses" endpoint rebuild the next-turn engine input without preserving the cache salt value. This causes the continuation prefix to be stored in the global unsalted cache namespace, even when the caller has enabled salting for tenant isolation. On deployments where prefix caching is enabled (the default setting), an authenticated tenant who can reconstruct a victim's low-entropy post-tool history can submit the same continuation and use the cached tokens per turn count to determine if the prefix was previously processed. This effectively creates a prompt-membership oracle that defeats the intended isolation of salted prefix caching.
Recommendations Update vLLM to version 0.30.0 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105752
GHSA-935W-9G4M-P28P

Affected Products

Vllm