{"data":{"id":"4eeacfc6-0ee7-4e8e-8d88-445fdf4b1240","title":"GHSA-2phq-3phc-84px: vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`","summary":"vLLM versions 0.25.1 and earlier have a security vulnerability in flash late-interaction scoring (a feature enabled by default), where query embeddings are cached using a request ID that comes directly from a caller-controlled HTTP header (`X-Request-Id`). An attacker can reuse another user's request ID to replace their cached query with their own, causing that user's documents to be scored against the wrong query, or trigger cache errors that crash requests.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-2phq-3phc-84px","publishedAt":"2026-10-05T23:42:39.000Z","cveId":"CVE-2026-105755","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":[],"issueType":"vulnerability","affectedPackages":["vllm@< 0.30.0 (fixed: 0.30.0)"],"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-10-05T23:42:39.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}