CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path
Vulnerability ID: CVE-2026-105752
CVSS Score: 3.1
Published: 2026-10-06
A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.
TL;DR
vLLM fails to propagate the cache partition salt during multi-turn tool execution continuations, exposing post-tool prompt prefixes in the shared global cache and creating a side-channel oracle for co-tenants.
Technical Details
- CWE ID: CWE-524, CWE-200
- Attack Vector: Network
- CVSS v3.1 Score: 3.1 (Low)
- EPSS Score: 0.00043
- Impact: Partial Tenant Cache Isolation Failure / Metadata Leakage
- Exploit Status: none
- KEV Status: Not Listed
Affected Systems
- vLLM engine deployments utilizing the multi-turn Responses API ('Harmony' path) with prefix caching enabled.
-
vLLM: < 0.30.0 (Fixed in:
0.30.0)
Code Analysis
Commit: 6a2a2bb
Harmony tool continuations drop cache_salt - restoring prefix-cache partitioning
Mitigation Strategies
- Upgrade the vLLM deployment to version 0.30.0 or newer.
- Disable global prefix caching via the startup configuration flag.
- Limit exposure by restricting multi-tenant access to multi-turn agent endpoints.
Remediation Steps:
- Identify all active vLLM container instances running versions prior to 0.30.0.
- In corporate environments where immediate upgrading is blocked, modify the container startup arguments to include --enable-prefix-caching=false to disable the caching side-channel.
- Update requirements.txt, pyproject.toml, or Dockerfiles to specify vllm>=0.30.0.
- Deploy the updated service images to the staging environment and verify that multi-turn API calls successfully output responses without errors.
- Perform rolling updates of the production instances to complete the remediation process.
References
- GitHub Security Advisory: GHSA-935w-9g4m-p28p
- NVD - CVE-2026-105752 Detail
- CVE.org Authority Record for CVE-2026-105752
- vLLM v0.30.0 Release Tag
Read the full report for CVE-2026-105752 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)