PT-2026-106263 · Vllm · Vllm

CVE-2026-105753

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.28.0
Description A cache-mirroring desynchronization exists in the default multimodal LRU cache when mm processor cache type is set to lru. The system mirrors state between a frontend sender cache (MultiModalProcessorSenderCache) and an engine receiver cache (MultiModalReceiverCache). If a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine receiver receives the payload (for example, due to a max model len rejection), the frontend cache incorrectly records the item as cached while the receiver cache remains empty.
A subsequent request using the same mm hash variable will trigger a cache hit in the frontend, causing it to send no payload. This leads the receiver cache to trigger an assertion failure in the get and update item() function with the message "Expected a cached item," resulting in a shared-service availability failure.
Recommendations Update vLLM to version 0.28.0 or later. As a temporary mitigation, avoid using the lru cache type for multimodal processing by changing the mm processor cache type configuration.

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105753
GHSA-PH3R-5JFG-F84F

Affected Products

Vllm