Database/AI/ML frameworks & serving
vLLM: unvalidated cache_salt raises an uncaught ValueError and terminates EngineCore
Impact
The OpenAI-compatible request models accepted any non-empty cache_salt without applying the character and length restrictions that LMCache-MP's IPCCacheServerKey consumer requires. On a deployment using the LMCache-MP connector, a salt containing a forbidden character or exceeding the permitted length raises an uncaught ValueError during scheduler cache lookup and terminates EngineCore, denying service to every concurrent user of that replica. This is a one-field, one-request kill of a shared GPU serving process - cheap to trigger repeatedly, and each recovery costs a weight reload. Only deployments wiring up the LMCache-MP KV connector are affected; no data disclosure is claimed.
Who can reach it
Any authenticated API client that can set cache_salt on a request to the OpenAI-compatible endpoint (CVSS AV:N/PR:L), on a deployment configured with the LMCache-MP connector.
What to do
Upgrade vLLM to 0.30.0 and restart the serving replicas. If upgrading has to wait, strip or validate cache_salt at the gateway in front of vLLM, or stop using the LMCache-MP connector - both are config changes plus a replica restart rather than node maintenance.
References
Related entries
- vLLM: structured-output request failures escape request scope and terminate the shared engineCVE-2026-105757 · vLLM structured-output path (grammar compilation, ngram_gpu speculative decoding, Rust frontend validation)Medium
- vLLM: unbounded frame count in video/jpeg base64 data URLs crashes the server with OOMCVE-2026-34755 · vLLM OpenAI-compatible API server (video/jpeg base64 multimodal path)Medium
- vLLM: no upper bound on the n parameter lets a single request OOM the API serverCVE-2026-34756 · vLLM OpenAI-compatible API server (ChatCompletionRequest/CompletionRequest n parameter)Medium
- vLLM (revision pinning): Revision pinning does not apply to all model artifactsCVE-2026-47155 · vLLM (revision pinning)Medium
- Starlette: malformed Host header makes request.url.path diverge from the routed pathCVE-2026-48710 · Starlette (Host header validation when reconstructing request.url)Medium
- vLLM - sampling parameter validation: Temperature validation uses strict comparison operators, so boundary values slipCVE-2026-54235 · vLLM - sampling parameter validationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.