6.5

CVE-2026-105753

vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, while the engine receiver cache never receives the payload if that request is rejected. A later request reusing the same media hash causes MultiModalProcessorSenderCache to send no payload and MultiModalReceiverCache to reach an assertion with the message "Expected a cached item," producing a shared-service availability failure. This issue is fixed in version 0.28.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vllm ≫ Vllm Version < 0.28.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.346
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

https://github.com/vllm-project/vllm/security/advisories/GHSA-ph3r-5jfg-f84f
Vendor Advisory
Mitigation
https://github.com/vllm-project/vllm/pull/46747
Patch
Issue Tracking
https://github.com/vllm-project/vllm/pull/51897
Patch
Issue Tracking
https://github.com/vllm-project/vllm/commit/396204230423b7cc6798300926b8fa30190d26a9
Patch
https://github.com/vllm-project/vllm/releases/tag/v0.28.0
Release Notes