PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105753 vllm-project CVE debrief

A vulnerability in vLLM's multimodal cache can lead to a desync between the frontend and engine core processes. This desync allows a later request reusing the same media hash to trip a receiver assertion in the engine core. The vulnerability arises when a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine core receives the item. As a result, the frontend believes the media is cached while the engine core never received it. This issue can cause a denial-of-service condition and potentially allow for code execution if an attacker can craft a malicious media hash. Defenders should prioritize verifying the version of vLLM in use,

Vendor
vllm-project
Product
vllm
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-08
Advisory published
2026-10-06
Advisory updated
2026-10-08

Who should care

Defenders responsible for maintaining and securing systems that use vLLM should prioritize verifying the version of vLLM in use. They should assess exposure to this vulnerability and take steps to remediate it. This includes reviewing compensating controls, monitoring for potential denial-of-service conditions or code execution attempts, and tracking exceptions. Affected operators, platforms, vulnerability-management teams, and security teams should be

Why it matters

A vulnerability in vLLM's multimodal cache can lead to a desync between the frontend and engine core processes, allowing a later request reusing the same media hash to trip a receiver assertion in the engine core. Defenders should prioritize verifying the version of vLLM in use and assessing exposure to this vulnerability.

  • Denial-of-service condition due to receiver assertion in the engine core
  • Potential for code execution if an attacker can craft a malicious media hash
  • Need for verification of vLLM version and exposure to this vulnerability

Technical summary

The vulnerability is caused by a desync between the frontend and engine core processes in vLLM's multimodal cache. When a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine core receives the item, the frontend believes the media is cached while the engine core never received it. A later request reusing the same media hash can then trip a receiver assertion in the engine core.

Defensive priority

Defenders should prioritize verifying the version of vLLM in use and assessing exposure to this vulnerability, as it could lead to a denial-of-service condition or potentially allow for code execution.

Recommended defensive actions

  • Verify the version of vLLM in use and update to a fixed version if necessary.
  • Assess exposure to this vulnerability and prioritize remediation.
  • Monitor for potential denial-of-service conditions or code execution attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is caused by a desync between the frontend and engine core processes in vLLM's multimodal cache. When a request is rejected after the frontend has rendered and hashed the multimodal input but before the engine core receives the item, the frontend believes the media is cached while the engine core never received it. A later request reusing the same media hash can then trip a receiver assertion in the engine core.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105753 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105753

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105753 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105753

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing t

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-ph3r-5jfg-f84f.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/security/advisories/GHSA-ph3r-5jfg-f84f

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/pull/46747

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/pull/51897

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/commit/396204230423b7cc6798300926b8fa30190d26a9

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vllm-project/vllm/releases/tag/v0.28.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.