{"data":{"id":"a492ff1c-de51-4959-8504-febad070208e","title":"CVE-2026-100647: vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-com","summary":"vLLM (a software framework for running large language models) versions before 0.29.0 have a denial-of-service vulnerability in the cache_salt parameter, which is a value used for caching. Because this parameter has no size limit and is processed by a single scheduler thread (the component that manages task execution), attackers can send huge amounts of data that force expensive computational operations, causing the system to freeze and reject all other requests.","solution":"Update vLLM to version 0.29.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100647","publishedAt":"2026-09-26T14:16:47.097Z","cveId":"CVE-2026-100647","cweIds":["CWE-20"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LlamaIndex"],"affectedVendorsRaw":["vLLM","OpenAI","Anthropic"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-26T14:16:47.097Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}