CVE-2026-105754
Received Received - Intake

Memory Corruption in vLLM EngineCore

Vulnerability report for CVE-2026-105754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_hashes field, ranges in the features.mm_placeholders field, and wire-selected multimodal field processors without rebinding them to the active model renderer contract. Forged grid geometry, field types, or non-positive placeholder lengths can terminate the shared EngineCore; when an attacker knows or can induce a victim's content hash, forged cache hashes can poison or retrieve cross-request encoder-cache state; and dropped sparse placeholder masks can alter replayed transport semantics. This issue is fixed in version 0.30.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vllm-project vllm < 0.30.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-704 The product does not correctly convert an object, resource, or structure from one type to a different type.
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in vLLM before 0.30.0 allows an attacker to manipulate tensor inputs, cache identifiers, and placeholder ranges via the /inference/v1/generate endpoint. This can cause the EngineCore to terminate or alter shared encoder-cache state if cache hashes are forged or known.

Detection Guidance

Detection requires checking the vLLM version in use. Run: vllm --version. If the version is below 0.30.0, the system is vulnerable. Inspect network traffic for requests to /inference/v1/generate with suspicious fields like features.kwargs_data, features.mm_hashes, or features.mm_placeholders.

Impact Analysis

An attacker could exploit this to crash the vLLM service, poison cached data, or retrieve sensitive information if they know or can guess content hashes. This may lead to denial of service or unauthorized access to cached encoder states.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, violating GDPR's integrity and confidentiality principles and HIPAA's safeguards for protected health information. Compliance may be compromised if sensitive data is exposed or corrupted.

Mitigation Strategies

Upgrade vLLM to version 0.30.0 or later immediately. Restrict access to the /inference/v1/generate endpoint to trusted users only. Monitor logs for unusual activity targeting this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart