CVE-2026-100647 | vllm-project vLLM up to 0.28.x EngineCore cache_salt denial of service
A vulnerability identified as problematic has been detected in vllm-project vLLM up to 0.28.x. The affected element is an unknown function of the component EngineCore. This manipulation of the argument cache_salt causes denial of service.
This vulnerability appears as CVE-2026-100647. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More