Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105755— vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`

Quick assessment

Affected
vllm-project vllm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

vLLM 是用于大型语言模型推理和服务的引擎。在 0.30.0 版本之前,/score 和 /rerank 端点的 flash 晚期交互评分机制从由调用者控制的 X-Request-Id 头部字段中派生每个工作进程(worker)的 query_key 值。一个并发请求如果复用了受害者的标识符,可以覆盖缓存中的查询嵌入(query embedding),导致受害者的文档被针对攻击者的查询进行评分;此外,共享使用的计数器也可能引发晚期交互缓存未命中错误。此问题已在 0.30.0 版本中得到修复。

CVSS 4.2 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105755

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Source: CVE Program / CVE List V5
Vulnerability Description
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached query embedding so the victim's documents are scored against the attacker's query, and shared use counters can also cause a late-interaction cache-miss error. This issue is fixed in version 0.30.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
vllm-project vllm < 030.0 -

II. Public POCs for CVE-2026-105755

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105755

请登录查看更多情报信息。

Other References for CVE-2026-105755 (4)

Same Patch Batch · vllm-project · 2026-10-05 · 9 CVEs total

CVE-2026-105753 6.5 MEDIUM vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reu
CVE-2026-105754 6.5 MEDIUM vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
CVE-2026-105756 6.5 MEDIUM vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP de
CVE-2026-105757 6.5 MEDIUM vLLM: Structured-output request errors escape the request boundary and terminate the share
CVE-2026-105759 5.9 MEDIUM vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens i
CVE-2026-105760 5.3 MEDIUM vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
CVE-2026-105758 5.3 MEDIUM vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the
CVE-2026-105752 3.1 LOW vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache

IV. Related Vulnerabilities

V. Comments for CVE-2026-105755

No comments yet


Leave a comment