GPU VulnDB

Database/AI/ML frameworks & serving

vLLM: unvalidated cache_salt raises an uncaught ValueError and terminates EngineCore

CVSS 6.5CVE-2026-105756AI/ML frameworks & servingcurated

Impact

The OpenAI-compatible request models accepted any non-empty cache_salt without applying the character and length restrictions that LMCache-MP's IPCCacheServerKey consumer requires. On a deployment using the LMCache-MP connector, a salt containing a forbidden character or exceeding the permitted length raises an uncaught ValueError during scheduler cache lookup and terminates EngineCore, denying service to every concurrent user of that replica. This is a one-field, one-request kill of a shared GPU serving process - cheap to trigger repeatedly, and each recovery costs a weight reload. Only deployments wiring up the LMCache-MP KV connector are affected; no data disclosure is claimed.

Who can reach it

Any authenticated API client that can set cache_salt on a request to the OpenAI-compatible endpoint (CVSS AV:N/PR:L), on a deployment configured with the LMCache-MP connector.

What to do

Upgrade vLLM to 0.30.0 and restart the serving replicas. If upgrading has to wait, strip or validate cache_salt at the gateway in front of vLLM, or stop using the LMCache-MP connector - both are config changes plus a replica restart rather than node maintenance.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.