VYPR
Vypr IntelligenceAI-generatedOct 6, 2026· 11 CVEs

VLLM: Batch of 11 Medium-Severity Vulnerabilities Disclosed Together

Eleven vulnerabilities disclosed for VLLM LLM engine on Oct 5-6, 2026, impacting versions prior to 0.30.0 and 0.31.0, with risks including DoS and out-of-bounds reads.

Key findings

  • Eleven CVEs disclosed for VLLM between Oct 5-6, 2026, affecting versions prior to 0.30.0 and 0.31.0.
  • Vulnerabilities include denial of service, out-of-bounds reads, and improper request parameter handling.
  • Issues identified in penalty handler, completions handler, caching, and request validation components.
  • CVSS scores range from 3.1 (Low) to 6.5 (Medium).
  • Users advised to update to VLLM 0.30.0 or 0.31.0 for mitigation.

On October 5-6, 2026, a batch of eleven security vulnerabilities was disclosed for the VLLM large language model inference and serving engine. These vulnerabilities, affecting versions prior to 0.30.0 and 0.31.0, span various components including the penalty handler, completions request handler, and caching mechanisms. The disclosures highlight potential risks such as denial of service, out-of-bounds reads, and improper handling of request parameters, with CVSS scores ranging from 3.1 (Low) to 6.5 (Medium).

Several vulnerabilities stem from improper handling of request parameters, particularly concerning media and video processing. CVE-2026-105760, CVE-2026-105758, and CVE-2026-105753 detail how VLLM versions prior to 0.30.0 and 0.28.0, respectively, accepted large values for fps and max_frames in media_io_kwargs without adequate server-side ceilings. This could allow attackers to construct oversized pre-computations, leading to denial of service. CVE-2026-105753 specifically points to issues with the mirrored multimodal LRU cache where media hashes could be committed before engine admission, potentially leading to cache inconsistencies.

Other vulnerabilities focus on request validation and data handling. CVE-2026-105759 describes how the Rust frontend's metric tracking middleware recorded raw HTTP method tokens as Prometheus labels, allowing unauthenticated attackers to send unique method tokens to unguarded routes, potentially leading to information disclosure or denial of service. CVE-2026-105757 highlights that structured-output request failures could escape validation and reach an engine core fatal-error path, potentially leading to denial of service. CVE-2026-105756 points to an issue where a non-empty cache_salt value could be accepted without proper character and length restrictions, impacting deployments using the LMCache-MP connector. CVE-2026-105755 details how flash late-interaction scoring could derive worker query_key values from the caller-controlled X-Request-Id header, allowing concurrent requests to overwrite cached query keys. CVE-2026-105754 describes how the /inference/v1/generate endpoint accepted caller-supplied tensors and cache identifiers without sufficient validation.

Two vulnerabilities relate to specific component flaws. CVE-2026-105922 in the Penalty Handler's get_token_bin_counts_and_mask function could lead to a denial of service. CVE-2026-105775 in the Completions Request Handler's conv_ssm_forward function could result in an out-of-bounds read. Finally, CVE-2026-105752 indicates that Harmony tool continuations could rebuild engine inputs without preserving the cache_salt, placing prefixes in the global unsalted cache namespace even when a salt was intended.

The affected versions are primarily prior to VLLM 0.30.0 and 0.31.0. Users are advised to update to patched versions to mitigate these risks. The broad range of issues across different components underscores the importance of regular security updates for large language model infrastructure.

The disclosures were made on October 5th and 6th, 2026, with the majority of vulnerabilities reported on October 5th. The span of 16 hours between the first and last disclosure suggests a coordinated release event.

The vulnerabilities disclosed include denial of service, out-of-bounds reads, and issues related to caching and request parameter handling.

Users of VLLM should update to versions 0.30.0 or 0.31.0, or later, to address these security flaws.

The batch of eleven CVEs disclosed between October 5-6, 2026, impacts VLLM versions prior to 0.30.0 and 0.31.0.

The vulnerabilities span denial of service, out-of-bounds reads, and improper request parameter handling across multiple components.

All disclosed vulnerabilities have been addressed in VLLM versions 0.30.0 and 0.31.0.

The issues range in severity, with CVSS scores from 3.1 (Low) to 6.5 (Medium).

The disclosures highlight potential risks in media processing, caching, and request validation within LLM serving engines.

Users are strongly recommended to update their VLLM installations to the latest available versions.

AI-written article. Grounded in 11 CVE records listed below.