CyberRota Analysis
AI-GeneratedVersions of vLLM prior to 0.29.0 are vulnerable to a denial-of-service attack due to inadequate length validation on the cache_salt parameter in OpenAI-compatible and Anthropic API endpoints. This flaw allows unauthenticated attackers to send oversized HTTP requests, leading to resource exhaustion and service disruption for all concurrent requests. Organizations using affected versions should prioritize patching to mitigate potential service outages.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thread. Unauthenticated attackers can send HTTP requests with multi-hundred-megabyte salt values that trigger expensive pickle serialization and SHA-256 hashing, stalling the scheduler thread and denying service to all concurrent requests.
Related CVEs
Other vulnerabilities affecting the same vendor(s)