GHSA-2phq-3phc-84px: vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
mediumvulnerability
security
Summary
vLLM versions 0.25.1 and earlier have a security vulnerability in flash late-interaction scoring (a feature enabled by default), where query embeddings are cached using a request ID that comes directly from a caller-controlled HTTP header (`X-Request-Id`). An attacker can reuse another user's request ID to replace their cached query with their own, causing that user's documents to be scored against the wrong query, or trigger cache errors that crash requests.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Disclosure Date
October 5, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrityavailability
AI Component TargetedInference
Affected Vendors
Affected Packages
vllm@< 0.30.0 (fixed: 0.30.0)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-2phq-3phc-84px
First tracked: October 5, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%