PT-2026-106264 · Vllm · Vllm
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.30.0
Description
In the disaggregated scale-out path, the
/inference/v1/generate endpoint fails to validate and rebind caller-supplied multimodal state against the active model's renderer contract. This allows an authenticated attacker to submit forged data through the features object, specifically affecting the kwargs data, mm hashes, and mm placeholders fields.This flaw can lead to several critical outcomes:
- Denial of Service: Forging grid geometry, field types, or providing non-positive placeholder lengths can cause an engine-fatal crash of the shared EngineCore process, resulting in a complete service outage for all tenants.
- Cache Poisoning and Disclosure: Because the
mm hashes(used as cache keys) are not bound to the actual payload, an attacker who knows or can induce a victim's content hash can poison or retrieve cross-request encoder-cache state. - Integrity Loss: Dropping sparse placeholder masks during the render-to-generate replay can alter transport semantics for models relying on these masks.
Recommendations
Update vLLM to version 0.30.0 or later.
As a temporary mitigation, restrict access to the
/inference/v1/generate endpoint to only trusted internal services to prevent unauthorized authenticated users from submitting forged multimodal payloads.Fix
IDOR
Assertion Failure
RCE
Exposure of Resource to Wrong Sphere
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vllm