CVE-2026-105756

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the character and length restrictions required by the IPCCacheServerKey consumer in LMCache-MP. On deployments using the LMCache-MP connector, a salt that contains a forbidden character or exceeds the permitted length can raise an uncaught ValueError during scheduler cache lookup, causing EngineCore to terminate and denying service to all concurrent users. This issue is fixed in version 0.30.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
By indicator
Full discourse1 post
  • Kaitan ID Security@KaitanSecurity

    ⚠️ HIGH — CVE-2026-105756 vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models ac… CVSS 6.5 ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-105756 #OpenAI #CyberSecurity #InfoSec

    0000028
    88 followersView on X

Explore more