Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105754— vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features

Quick assessment

Affected
vllm-project vllm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

vLLM 是一个用于大语言模型的推理和服务引擎。在 0.30.0 版本之前,在分布式扩展路径中,/inference/v1/generate 端点接受由调用方提供的张量(存储在 features.kwargs_data 字段中)、缓存标识符(存储在 features.mm_hashes 字段中)、范围(存储在 features.mm_placeholders 字段中),以及通过协议选定的多模态字段处理器,但这些输入未被重新绑定到当前活动的模型渲染器契约中。伪造的网格几何结构、字段类型或非正的占位符长度可能导致共享的

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105754

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Source: CVE Program / CVE List V5
Vulnerability Description
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_hashes field, ranges in the features.mm_placeholders field, and wire-selected multimodal field processors without rebinding them to the active model renderer contract. Forged grid geometry, field types, or non-positive placeholder lengths can terminate the shared EngineCore; when an attacker knows or can induce a victim's content hash, forged cache hashes can poison or retrieve cross-request encoder-cache state; and dropped sparse placeholder masks can alter replayed transport semantics. This issue is fixed in version 0.30.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
vllm-project vllm < 0.30.0 -

II. Public POCs for CVE-2026-105754

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105754

请登录查看更多情报信息。

Other References for CVE-2026-105754 (4)

Same Patch Batch · vllm-project · 2026-10-05 · 9 CVEs total

CVE-2026-105753 6.5 MEDIUM vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reu
CVE-2026-105756 6.5 MEDIUM vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP de
CVE-2026-105757 6.5 MEDIUM vLLM: Structured-output request errors escape the request boundary and terminate the share
CVE-2026-105759 5.9 MEDIUM vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens i
CVE-2026-105760 5.3 MEDIUM vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
CVE-2026-105758 5.3 MEDIUM vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the
CVE-2026-105755 4.2 MEDIUM vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled req
CVE-2026-105752 3.1 LOW vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache

IV. Related Vulnerabilities

V. Comments for CVE-2026-105754

No comments yet


Leave a comment