Reversible One-Way Hash in vLLM - CVE-2025-25183
Published: February 6, 2025 / Updated: May 1, 2026
vLLM
Detailed vulnerability description
The vulnerability allows a remote user to interfere with subsequent responses.
The vulnerability exists due to predictable hash collisions in the prefix cache when processing maliciously constructed prompts. A remote user can intentionally populate the cache with a colliding prompt to interfere with subsequent responses.
User interaction is required.