LowVulnerabilityLLM-specific
CVE-2026-105752: vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105752
- Published
- Record updated
Summary
vLLM versions prior to 0.30.0 drop the cache_salt value when rebuilding the next-turn engine input for Harmony tool continuations submitted through POST /v1/responses. The continuation prefix lands in the global unsalted cache namespace even when the caller enabled salting, and on deployments with prefix caching enabled (the default), an authenticated tenant can use the cached_tokens_per_turn count to determine whether a victim's low-entropy post-tool prefix was previously processed, defeating salted prefix cache isolation.
Mitigation
Fixed in version 0.30.0.
Topics
Related items
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database
- MediumEncrypted instructions trick Copilot CLI into spilling developer secretsSimilar attack · CSO Online
- HighCVE-2026-93677: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database
- HighCVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database