CVE-2026-105753
Received Received - Intake

vLLM Multimodal Cache Rejection Denial of Service

Vulnerability report for CVE-2026-105753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, while the engine receiver cache never receives the payload if that request is rejected. A later request reusing the same media hash causes MultiModalProcessorSenderCache to send no payload and MultiModalReceiverCache to reach an assertion with the message "Expected a cached item," producing a shared-service availability failure. This issue is fixed in version 0.28.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vllm-project vllm < 0.28.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in vLLM before version 0.28.0 involves a mirrored multimodal LRU cache issue. When a request with media content is rejected after the frontend cache commits a media hash but before the engine receives it, a later request reusing the same hash causes a cache mismatch. This leads to the receiver cache failing with an assertion error and crashing the service.

Detection Guidance

Detection requires checking the vLLM version in use. Run 'pip show vllm' or 'vllm --version' to verify if the installed version is below 0.28.0. If so, the system is vulnerable.

Impact Analysis

If you use vLLM for serving large language models, this flaw could cause unexpected service outages. Requests may fail or the system may crash when processing multimodal content, disrupting your AI services and requiring manual intervention to restore functionality.

Compliance Impact

The vulnerability could lead to service availability failures, potentially disrupting access to critical systems. This may impact compliance with GDPR (availability principle) or HIPAA (accessibility requirements) if systems handling sensitive data are affected. However, the provided CVE data does not explicitly detail compliance impacts.

Mitigation Strategies

Upgrade vLLM to version 0.28.0 or later immediately. Use 'pip install --upgrade vllm' or update via your package manager. Ensure no running instances use the vulnerable version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart