Description
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached query embedding so the victim's documents are scored against the attacker's query, and shared use counters can also cause a late-interaction cache-miss error. This issue is fixed in version 0.30.0.
Published: 2026-10-05
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Scoring integrity compromise
Action: Patch
AI Analysis

Impact

vLLM is an inference engine for large language models. The flaw allows a caller‑supplied X-Request-Id header to be used as a cache key for query embeddings at the /score and /rerank endpoints. A malicious user can send a request that shares a victim’s request identifier and overwrite the cached embedding, causing the victim’s documents to be evaluated against the attacker’s query. This defect also can trigger late‑interaction cache‑miss errors that may disrupt scoring operation. The impact is a loss of integrity for query scoring and potential service disruption, but it does not grant arbitrary code execution or data exfiltration.

Affected Systems

The vulnerability exists in the vllm project’s vllm engine. All releases prior to version 0.30.0 are affected; the problem is fixed starting with v0.30.0.

Risk and Exploitability

The CVSS score of 4.2 places the issue in the medium risk range. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have network access to the /score or /rerank endpoint and to know or guess a victim’s X-Request-Id value. A concurrent request bearing the same identifier can overwrite the cache and trigger the vulnerability. Given these prerequisites, the likelihood of exploitation is moderate and the damage is limited to scoring integrity and possible availability problems.

Generated by OpenCVE AI on October 6, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the vllm engine to version 0.30.0 or later where the cache key is no longer derived from the caller‑controlled header.
  • Configure the application to generate and enforce a server‑side unique identifier for caching instead of accepting client supplied values on the /score and /rerank endpoints.
  • Monitor logs for cache‑miss errors or abnormal scoring results that could indicate abuse of a shared request ID.

Generated by OpenCVE AI on October 6, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2phq-3phc-84px vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
History

Tue, 06 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Vllm-project
Vllm-project vllm
Vendors & Products Vllm-project
Vllm-project vllm

Mon, 05 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached query embedding so the victim's documents are scored against the attacker's query, and shared use counters can also cause a late-interaction cache-miss error. This issue is fixed in version 0.30.0.
Title vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Vllm-project Vllm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T22:47:54.854Z

Reserved: 2026-10-05T19:11:07.947Z

Link: CVE-2026-105755

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T23:17:02.167

Modified: 2026-10-05T23:17:02.167

Link: CVE-2026-105755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T00:30:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key