Description
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the character and length restrictions required by the IPCCacheServerKey consumer in LMCache-MP. On deployments using the LMCache-MP connector, a salt that contains a forbidden character or exceeds the permitted length can raise an uncaught ValueError during scheduler cache lookup, causing EngineCore to terminate and denying service to all concurrent users. This issue is fixed in version 0.30.0.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

vLLM is an inference engine for large language models that exposes OpenAI-compatible request models. In versions earlier than 0.30.0, the validation of the cache_salt parameter is too permissive. Its characters and length are allowed to exceed the restrictions required by the IPCCacheServerKey consumer in the LMCache-MP connector. When a request supplies a cache_salt containing a forbidden character or a length that is too large, the scheduler cache lookup throws an uncaught ValueError. This exception terminates the EngineCore process, which causes all concurrent users to experience a denial of service. The weakness is an input validation flaw that can lead to application misbehaviour and availability loss.

Affected Systems

vLLM is the affected product. Any deployment of vLLM using the LMCache-MP connector and running a version earlier than 0.30.0 is vulnerable. The fix is available in release 0.30.0.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is triggered by a single crafted request and can crash the core service, the practical impact on availability can be significant for any user of the affected deployment. However, no public exploit is known, and there is no stated EPSS score. The attack vector is inferred to be network via an OpenAI-compatible API call, as that is how the cache_salt is supplied.

Generated by OpenCVE AI on October 6, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vLLM to version v0.30.0 or later to apply the validated cache_salt enforcement
  • Ensure that the LMCache-MP connector is correctly configured so that cache_salt values are supplied only by trusted components
  • Verify that your deployment excludes any legacy API endpoints that accept unvalidated cache_salt parameters

Generated by OpenCVE AI on October 6, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2823-qmq8-rwvj vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
History

Tue, 06 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Vllm-project
Vllm-project vllm
Vendors & Products Vllm-project
Vllm-project vllm

Mon, 05 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the character and length restrictions required by the IPCCacheServerKey consumer in LMCache-MP. On deployments using the LMCache-MP connector, a salt that contains a forbidden character or exceeds the permitted length can raise an uncaught ValueError during scheduler cache lookup, causing EngineCore to terminate and denying service to all concurrent users. This issue is fixed in version 0.30.0.
Title vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Weaknesses CWE-20
CWE-248
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Vllm-project Vllm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T22:49:59.642Z

Reserved: 2026-10-05T19:11:07.947Z

Link: CVE-2026-105756

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T23:17:02.317

Modified: 2026-10-05T23:17:02.317

Link: CVE-2026-105756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T00:30:18Z

Weaknesses