CVE-2026-100647: vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-com
Summary
vLLM (a software framework for running large language models) versions before 0.29.0 have a denial-of-service vulnerability in the cache_salt parameter, which is a value used for caching. Because this parameter has no size limit and is processed by a single scheduler thread (the component that manages task execution), attackers can send huge amounts of data that force expensive computational operations, causing the system to freeze and reject all other requests.
Solution / Mitigation
Update vLLM to version 0.29.0 or later.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
network
low
none
none
September 26, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-100647
First tracked: September 26, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%