CVE-2026-105752: vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
On the GPT-OSS “Harmony” path (POST /v1/responses), a request that uses a built-in or MCP tool runs as a multi-turn loop: after each tool call vLLM re-renders the full next-turn Harmony prompt and re-submits it to the engine. Turn 1 correctly carries request.cache_salt, but the tool-continuation re-submission rebuilds the engine input via tokens_input(token_ids) with no cache_salt. The continuation prefix is therefore cached in the global unsalted namespace even though the caller opted into salting. A second tenant who can guess the low-entropy post-tool history submits the reconstructed continuation (unsalted) and reads exact per-turn cached-token counts from the Responses usage — restoring the prompt-membership oracle that cache_salt is documented to prevent.
Silently dropping a preserved salt after the supported tool workflow is enabled is a broken isolation control: the caller enabled salting and every turn should stay isolated, but continuation turns leak into the shared cache.
This is distinct from GHSA-4qjh-9fv9-r85r (CVE-2025-46570): that advisory is the prefix-cache membership oracle for which cache_salt is the documented mitigation, and its PR-17045 fix does not close this site — the Harmony tool continuation silently drops the preserved salt, caching in the unsalted namespace and leaking exact cached_tokens_per_turn counts from a different sink (the Responses serving continuation, not general TTFT timing).
References
- github.com/advisories/GHSA-935w-9g4m-p28p
- github.com/vllm-project/vllm/commit/6a2a2bb02b563b83f946012959fd3927984d072a
- github.com/vllm-project/vllm/pull/50195
- github.com/vllm-project/vllm/pull/51818
- github.com/vllm-project/vllm/releases/tag/v0.30.0
- github.com/vllm-project/vllm/security/advisories/GHSA-935w-9g4m-p28p
- nvd.nist.gov/vuln/detail/CVE-2026-105752
Code Behaviors & Features
Detect and mitigate CVE-2026-105752 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →