PT-2026-106264 · Vllm · Vllm

·

CVE-2026-105754

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.30.0
Description In the disaggregated scale-out path, the /inference/v1/generate endpoint fails to validate and rebind caller-supplied multimodal state against the active model's renderer contract. This allows an authenticated attacker to submit forged data through the features object, specifically affecting the kwargs data, mm hashes, and mm placeholders fields.
This flaw can lead to several critical outcomes:
  • Denial of Service: Forging grid geometry, field types, or providing non-positive placeholder lengths can cause an engine-fatal crash of the shared EngineCore process, resulting in a complete service outage for all tenants.
  • Cache Poisoning and Disclosure: Because the mm hashes (used as cache keys) are not bound to the actual payload, an attacker who knows or can induce a victim's content hash can poison or retrieve cross-request encoder-cache state.
  • Integrity Loss: Dropping sparse placeholder masks during the render-to-generate replay can alter transport semantics for models relying on these masks.
Recommendations Update vLLM to version 0.30.0 or later. As a temporary mitigation, restrict access to the /inference/v1/generate endpoint to only trusted internal services to prevent unauthorized authenticated users from submitting forged multimodal payloads.

Fix

IDOR

Assertion Failure

RCE

Exposure of Resource to Wrong Sphere

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-105754
GHSA-PH72-CQR5-QPP7

Affected Products

Vllm