CYBER CODE RED

Get real-time updates on Telegram

P5Verified

vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`

CVE-2026-105755 affects vllm. CVSS base score 4.2 (MEDIUM, Vendor/CNA). Affected range: < 0.30.0. Fixed version: 0.30.0.

Published

CVE
CVE-2026-105755
CWE
CWE-639
Product
vllm
CCR priority
16.8 /100 (P5)
CVSS
4.2 /10 · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L · Vendor/CNA
KEV
no

Affected products

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-105755.html