CVE-2026-105754

MEDIUM CVSS 3.1: 6.5 EPSS 0.27%
Updated Oct 08, 2026
Vllm-Project
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 0.30.0
Fixed In 0.30.0
Type CWE-639 (Authorization Bypass), CWE-617, CWE-668 (Exposure of Resource to Wrong Sphere), CWE-20 (Improper Input Validation), CWE-704, CWE-1284
Vendor Vllm-Project
Public PoC No

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_hashes field, ranges in the features.mm_placeholders field, and wire-selected multimodal field processors without rebinding them to the active model renderer contract. Forged grid geometry, field types, or non-positive placeholder lengths can terminate the shared EngineCore; when an attacker knows or can induce a victim's content hash, forged cache hashes can poison or retrieve cross-request encoder-cache state; and dropped sparse placeholder masks can alter replayed transport semantics.

This issue is fixed in version 0.30.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Vllm Vllm
cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
— 0.30.0