6.5
CVE-2026-105753
- EPSS 0.43%
- Veröffentlicht 05.10.2026 22:37:19
- Zuletzt bearbeitet 08.10.2026 01:29:33
- Erkennungen
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, while the engine receiver cache never receives the payload if that request is rejected. A later request reusing the same media hash causes MultiModalProcessorSenderCache to send no payload and MultiModalReceiverCache to reach an assertion with the message "Expected a cached item," producing a shared-service availability failure. This issue is fixed in version 0.28.0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.346 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://github.com/vllm-project/vllm/security/advisories/GHSA-ph3r-5jfg-f84f
https://github.com/vllm-project/vllm/pull/46747
https://github.com/vllm-project/vllm/pull/51897
https://github.com/vllm-project/vllm/commit/396204230423b7cc6798300926b8fa30190d26a9
https://github.com/vllm-project/vllm/releases/tag/v0.28.0