Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105752— vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle

Quick assessment

Affected
vllm-project vllm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

vLLM 是一个用于大语言模型的推理和服务引擎。在 0.30.0 版本之前,Harmony 工具续传请求通过 “POST /v1/responses” 提交时,会重新构建下一轮的引擎输入,但未保留 值,从而将续传前缀写入全局无盐缓存命名空间,即使调用方启用了加盐机制。在启用前缀缓存(默认开启)的部署环境中,已认证的租户若能重构受害者的低熵工具后处理历史,则可提交相同的续传请求,并利用 计数判断该前缀是否曾被处理过,从而破坏加盐前缀缓存所期望的租户隔离机制。此问题已在 0.30.0 版本中得到修复。

CVSS 3.1 · Low

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105752

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Source: CVE Program / CVE List V5
Vulnerability Description
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations submitted through "POST /v1/responses" requests rebuild the next-turn engine input without preserving the cache_salt value, placing the continuation prefix in the global unsalted cache namespace even when the caller enabled salting. On deployments with prefix caching enabled, which is the default, an authenticated tenant who can reconstruct a victim's low-entropy post-tool history can submit the same continuation and use the cached_tokens_per_turn count to determine whether the prefix was previously processed, defeating the intended tenant isolation of salted prefix caching. This issue is fixed in version 0.30.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
vllm-project vllm < 0.30.0 -

II. Public POCs for CVE-2026-105752

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105752

请登录查看更多情报信息。

Other References for CVE-2026-105752 (5)

Same Patch Batch · vllm-project · 2026-10-05 · 9 CVEs total

CVE-2026-105753 6.5 MEDIUM vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reu
CVE-2026-105754 6.5 MEDIUM vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
CVE-2026-105756 6.5 MEDIUM vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP de
CVE-2026-105757 6.5 MEDIUM vLLM: Structured-output request errors escape the request boundary and terminate the share
CVE-2026-105759 5.9 MEDIUM vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens i
CVE-2026-105760 5.3 MEDIUM vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
CVE-2026-105758 5.3 MEDIUM vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the
CVE-2026-105755 4.2 MEDIUM vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled req

IV. Related Vulnerabilities

V. Comments for CVE-2026-105752

No comments yet


Leave a comment