{"data":{"id":"9eb610b1-3590-4426-8047-cff25abff510","title":"CVE-2026-105753: vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU ","summary":"vLLM (a system for running large language models) has a bug in versions before 0.28.0 where its multimodal cache (a storage system that keeps frequently used media files) can store media in one part of the system but not another, causing crashes when that media is reused later. When a second request tries to use the same cached media, the system fails with an error message and becomes unavailable.","solution":"Update to vLLM version 0.28.0 or later, where this issue is fixed.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105753","publishedAt":"2026-10-05T23:17:01.867Z","cveId":"CVE-2026-105753","cweIds":["CWE-617"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-10-05T23:17:01.867Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}