DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105752: CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

Vulnerability ID: CVE-2026-105752
CVSS Score: 3.1
Published: 2026-10-06

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

TL;DR

vLLM fails to propagate the cache partition salt during multi-turn tool execution continuations, exposing post-tool prompt prefixes in the shared global cache and creating a side-channel oracle for co-tenants.


Technical Details

  • CWE ID: CWE-524, CWE-200
  • Attack Vector: Network
  • CVSS v3.1 Score: 3.1 (Low)
  • EPSS Score: 0.00043
  • Impact: Partial Tenant Cache Isolation Failure / Metadata Leakage
  • Exploit Status: none
  • KEV Status: Not Listed

Affected Systems

  • vLLM engine deployments utilizing the multi-turn Responses API ('Harmony' path) with prefix caching enabled.
  • vLLM: < 0.30.0 (Fixed in: 0.30.0)

Code Analysis

Commit: 6a2a2bb

Harmony tool continuations drop cache_salt - restoring prefix-cache partitioning

Mitigation Strategies

  • Upgrade the vLLM deployment to version 0.30.0 or newer.
  • Disable global prefix caching via the startup configuration flag.
  • Limit exposure by restricting multi-tenant access to multi-turn agent endpoints.

Remediation Steps:

  1. Identify all active vLLM container instances running versions prior to 0.30.0.
  2. In corporate environments where immediate upgrading is blocked, modify the container startup arguments to include --enable-prefix-caching=false to disable the caching side-channel.
  3. Update requirements.txt, pyproject.toml, or Dockerfiles to specify vllm>=0.30.0.
  4. Deploy the updated service images to the staging environment and verify that multi-turn API calls successfully output responses without errors.
  5. Perform rolling updates of the production instances to complete the remediation process.

References


Read the full report for CVE-2026-105752 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)