Answer in brief
CVE-2026-105755 records a Medium severity (CVSS 4.2) vulnerability in vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`. The current sources do not mark it as known exploited. The current feed maps vllm-project/vllm (generic), vllm (pip). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 4.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps vllm-project/vllm (generic), vllm (pip). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| vllm-project/vllmgeneric | <030.0 | 030.0 |
| vllmpip | <0.30.0 | 0.30.0 |
Published upstream
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 5, 2026
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached query embedding so the victim's documents are scored against the attacker's query, and shared use counters can also cause a late-interaction cache-miss error. This issue is fixed in version 0.30.0.
Quoted source text, attributed separately from HOL analysis.