{"id":"CVE-2026-105754","title":"vLLM is an inference and serving engine for large language models","summary":"vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifi…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20","CWE-617","CWE-639","CWE-668","CWE-704","CWE-1284"],"vendor":"vllm-project","product":"vllm","affected":["vllm < 0.30.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T23:17:02.017","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105754","references":[{"url":"https://github.com/vllm-project/vllm/commit/1970f3ed4be7fa8620e4ddc4a12c36a8384cfc27","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/pull/51898","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-ph72-cqr5-qpp7","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-ph72-cqr5-qpp7"}],"tags":["nvd","cve.org","ghsa","pip"],"ingestedAt":"2026-10-05T23:36:21.156Z","aliases":["GHSA-ph72-cqr5-qpp7"],"ecosystem":"pip","patched":["vllm 0.30.0"],"slug":"CVE-2026-105754","body":"## Overview\n\nvLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_hashes field, ranges in the features.mm_placeholders field, and wire-selected multimodal field processors without rebinding them to the active model renderer contract. Forged grid geometry, field types, or non-positive placeholder lengths can terminate the shared EngineCore; when an attacker knows or can induce a victim's content hash, forged cache hashes can poison or retrieve cross-request encoder-cache state; and dropped sparse placeholder masks can alter replayed transport semantics. This issue is fixed in version 0.30.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-105754)\n\nAffected packages:\n\n- `vllm < 0.30.0`\n\nPatched in:\n\n- `vllm 0.30.0`\n\nSource: https://github.com/advisories/GHSA-ph72-cqr5-qpp7","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}