CVE-2026-105775
Received Received - Intake

Out-of-Bounds Read in vLLM Completions Request Handler

Vulnerability report for CVE-2026-105775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 31 associated CPEs
Vendor Product Version / Range
vllm-project vLLM 0.1
vllm-project vLLM 0.2
vllm-project vLLM 0.3
vllm-project vLLM 0.4
vllm-project vLLM 0.5
vllm-project vLLM 0.6
vllm-project vLLM 0.7
vllm-project vLLM 0.8
vllm-project vLLM 0.9
vllm-project vLLM 0.10
vllm-project vLLM 0.11
vllm-project vLLM 0.12
vllm-project vLLM 0.13
vllm-project vLLM 0.14
vllm-project vLLM 0.15
vllm-project vLLM 0.16
vllm-project vLLM 0.17
vllm-project vLLM 0.18
vllm-project vLLM 0.19
vllm-project vLLM 0.20
vllm-project vLLM 0.21
vllm-project vLLM 0.22
vllm-project vLLM 0.23
vllm-project vLLM 0.24
vllm-project vLLM 0.25
vllm-project vLLM 0.26
vllm-project vLLM 0.27
vllm-project vLLM 0.28
vllm-project vLLM 0.29
vllm-project vLLM 0.30
vllm-project vLLM 0.31.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read in the vLLM project affecting versions up to 0.31.0. It occurs in the conv_ssm_forward function of the MambaMixer2 layer when handling SSM state writes with Hybrid Mamba2, prefix caching, and a specific mamba-block-size parameter. The issue arises from incorrect handling of strided slices that produce empty tensors, causing a shape mismatch error and crashing the EngineCore.

Detection Guidance

Check if your vLLM instance is running version 0.31.0 or earlier. Look for crashes in the EngineCore with errors like 'shape mismatch' or 'RuntimeError' in logs related to conv_ssm_forward. Monitor for concurrent requests with shared prefixes not aligned to block sizes when using --mamba-block-size.

Impact Analysis

This vulnerability can cause crashes in the vLLM EngineCore when processing concurrent requests with shared prefixes of varying lengths. The crash occurs due to misalignment in the state cache, leading to runtime errors and potential denial of service. Attackers could exploit this remotely to disrupt service.

Compliance Impact

The vulnerability may impact compliance with GDPR and HIPAA due to potential unauthorized data access or processing disruptions caused by crashes in the EngineCore. Out-of-bounds reads could lead to data leaks or integrity issues, violating confidentiality and availability requirements under these regulations.

Mitigation Strategies

Update vLLM to a version that includes the fix for CVE-2026-105775. If updating is not possible, add the --mamba-cache-mode align flag to ensure state is cached only at block-aligned positions. Avoid using --mamba-block-size with Hybrid Mamba2 and prefix caching to prevent misalignment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart