Database/AI/ML frameworks & serving
vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' prompts
CVSS 2.6CVE-2025-46570AI/ML frameworks & servingcurated
Impact
Prefix-cache timing side channel leaks other tenants' prompts
Who can reach it
Co-tenant issuing timed prompts against a shared serving instance
What to do
No clean fix while prefix caching is shared. Do not share a vLLM instance across tenants — the cache is a cross-tenant channel
References
Related entries
- vLLM: unvalidated bad_words token indices corrupt logits of other in-flight requestsCVE-2026-93989 · vLLM sampling parameters (bad_words token index validation)Low
- Langflow: authenticated user reaches eval() through component input options and runs code on the hostCVE-2026-101861 · Langflow schema.py (eval() on component input option values)Low
- mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference serverCVE-2026-75090 · mistral.rs GGUF tokenizer (convert_gguf_to_hf_tokenizer)Low
- Ollama: integer overflow in the GGUF v1 string reader when parsing a crafted model fileCVE-2026-86289 · Ollama GGUF decoder (readGGUFV1String in fs/ggml/gguf.go)Low
- vLLM: attacker-supplied chat_template burns server resources on the GPU nodeCVE-2026-90878 · vLLM OpenAI-compatible server (/v1/chat/completions Jinja chat_template rendering)Low
- vLLM: malformed tiktoken vocab file crashes the tokenizer backend, denying service on the GPU nodeCVE-2026-90713 · vLLM (Rust tiktoken vocab file handler, TiktokenTokenizer::new)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.