PatchSiren cyber security CVE debrief
CVE-2026-105753 vllm-project CVE debrief
A vulnerability in vLLM's multimodal cache can lead to a desync between the frontend and engine core processes. This desync allows a later request reusing the same media hash to trip a receiver assertion in the engine core. The vulnerability arises when a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine core receives the item. As a result, the frontend believes the media is cached while the engine core never received it. This issue can cause a denial-of-service condition and potentially allow for code execution if an attacker can craft a malicious media hash. Defenders should prioritize verifying the version of vLLM in use,
- Vendor
- vllm-project
- Product
- vllm
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for maintaining and securing systems that use vLLM should prioritize verifying the version of vLLM in use. They should assess exposure to this vulnerability and take steps to remediate it. This includes reviewing compensating controls, monitoring for potential denial-of-service conditions or code execution attempts, and tracking exceptions. Affected operators, platforms, vulnerability-management teams, and security teams should be
Why it matters
A vulnerability in vLLM's multimodal cache can lead to a desync between the frontend and engine core processes, allowing a later request reusing the same media hash to trip a receiver assertion in the engine core. Defenders should prioritize verifying the version of vLLM in use and assessing exposure to this vulnerability.
- Denial-of-service condition due to receiver assertion in the engine core
- Potential for code execution if an attacker can craft a malicious media hash
- Need for verification of vLLM version and exposure to this vulnerability
Technical summary
The vulnerability is caused by a desync between the frontend and engine core processes in vLLM's multimodal cache. When a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine core receives the item, the frontend believes the media is cached while the engine core never received it. A later request reusing the same media hash can then trip a receiver assertion in the engine core.
Defensive priority
Defenders should prioritize verifying the version of vLLM in use and assessing exposure to this vulnerability, as it could lead to a denial-of-service condition or potentially allow for code execution.
Recommended defensive actions
- Verify the version of vLLM in use and update to a fixed version if necessary.
- Assess exposure to this vulnerability and prioritize remediation.
- Monitor for potential denial-of-service conditions or code execution attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is caused by a desync between the frontend and engine core processes in vLLM's multimodal cache. When a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine core receives the item, the frontend believes the media is cached while the engine core never received it. A later request reusing the same media hash can then trip a receiver assertion in the engine core.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105753 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105753
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105753 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105753
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing t
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-ph3r-5jfg-f84f.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/security/advisories/GHSA-ph3r-5jfg-f84f
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/pull/46747
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/pull/51897
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/commit/396204230423b7cc6798300926b8fa30190d26a9
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/releases/tag/v0.28.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.