PT-2026-35459 · Vllm · Vllm
Zyz3366
·
Published
2026-04-27
·
Updated
2026-04-27
·
CVE-2026-7141
CVSS v3.1
5.6
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
vllm versions prior to 0.19.0
Description
A flaw in the KV Block Handler component, specifically within the
has mamba layers() function of the vllm/v1/kv cache interface.py file, allows for an uninitialized resource through manipulation. This issue can be triggered remotely, although the attack complexity is high and exploitability is difficult.Recommendations
Deploy patch 1ad67864c0c20f167929e64c875f5c28e1aad9fd for versions prior to 0.19.0.
As a temporary workaround, restrict access to the
has mamba layers() function to minimize the risk of exploitation.Exploit
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm