๐Ÿ” CVE Alert

CVE-2026-105752

LOW 3.1

vLLM: Harmony tool continuations drop `cache_salt` โ€” restoring a cross-tenant prefix-cache membership oracle

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations submitted through "POST /v1/responses" requests rebuild the next-turn engine input without preserving the cache_salt value, placing the continuation prefix in the global unsalted cache namespace even when the caller enabled salting. On deployments with prefix caching enabled, which is the default, an authenticated tenant who can reconstruct a victim's low-entropy post-tool history can submit the same continuation and use the cached_tokens_per_turn count to determine whether the prefix was previously processed, defeating the intended tenant isolation of salted prefix caching. This issue is fixed in version 0.30.0.

CWE CWE-200 CWE-524
Vendor vllm-project
Product vllm
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for vllm-project vllm

Be the first to know when new low vulnerabilities affecting vllm-project vllm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

vllm-project / vllm
< 0.30.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vllm-project/vllm/security/advisories/GHSA-935w-9g4m-p28p github.com: https://github.com/vllm-project/vllm/pull/50195 github.com: https://github.com/vllm-project/vllm/pull/51818 github.com: https://github.com/vllm-project/vllm/commit/6a2a2bb02b563b83f946012959fd3927984d072a github.com: https://github.com/vllm-project/vllm/releases/tag/v0.30.0