OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-100647

MEDIUM · CVSS 5.3 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions of vLLM prior to 0.29.0 are vulnerable to a denial-of-service attack due to inadequate length validation on the cache_salt parameter in OpenAI-compatible and Anthropic API endpoints. This flaw allows unauthenticated attackers to send oversized HTTP requests, leading to resource exhaustion and service disruption for all concurrent requests. Organizations using affected versions should prioritize patching to mitigate potential service outages.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100647
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%

Original NVD Description

vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thread. Unauthenticated attackers can send HTTP requests with multi-hundred-megabyte salt values that trigger expensive pickle serialization and SHA-256 hashing, stalling the scheduler thread and denying service to all concurrent requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)