<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T06:33:17.646168+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03423</id>
    <title>bdu:2026-03423</title>
    <updated>2026-10-09T06:33:17.653632+00:00</updated>
    <content>bdu:2026-03423</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1057</id>
    <title>certfr-2025-avi-1057 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-09T06:33:17.653671+00:00</updated>
    <content>certfr-2025-avi-1057</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241916</id>
    <title>EUVD-2026-241916</title>
    <updated>2026-10-09T06:33:17.653690+00:00</updated>
    <content>EUVD-2026-241916</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46570</id>
    <title>fkie_cve-2025-46570</title>
    <updated>2026-10-09T06:33:17.653702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). These timing differences caused by matching chunks are significant enough to be recognized and exploited. This issue has been patched in version 0.9.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-46570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4qjh-9fv9-r85r</id>
    <title>GHSA-4qjh-9fv9-r85r — Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching</title>
    <updated>2026-10-09T06:33:17.653733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>This issue arises from the prefix caching mechanism, which may expose the system to a timing side-channel attack.</p>
<p>## Description
When a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). Our tests revealed that the timing differences caused by matching chunks are significant enough to be recognized and exploited.</p>
<p>For instance, if the victim has submitted a sensitive prompt or if a valuable system prompt has been cached, an attacker sharing the same backend could attempt to guess the victim's input. By measuring the TTFT based on prefix matches, the attacker could verify if their guess is correct, leading to potential leakage of private information.</p>
<p>Unlike token-by-token sharing mechanisms, vLLM’s chunk-based approach (PageAttention) processes tokens in larger units (chunks). In our tests, with chunk_size=2, the timing differences became noticeable enough to allow attackers to infer whether portions of their input match the victim's prompt at the chunk level.</p>
<p>## Environment</p>
<p>- GPU: NVIDIA A100 (40G)
- CUDA: 11.8
- PyTorch: 2.3.1
- OS: Ubuntu 18.04
- vLLM: v0.5.1
Configuration: We launched vLLM using the default settings and adjusted chunk_size=2 to evaluate the TTFT.</p>
<p>## Leakage
We conducted our tests using LLaMA2-70B-GPTQ on a single device. We analyzed the timing differences when prompts shared prefixes of 2 chunks, and plotted the corresponding ROC c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4qjh-9fv9-r85r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-53</id>
    <title>PYSEC-2025-53</title>
    <updated>2026-10-09T06:33:17.653783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vllm</p>
<p>vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). These timing differences caused by matching chunks are significant enough to be recognized and exploited. This issue has been patched in version 0.9.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-53"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3604</id>
    <title>WID-SEC-W-2026-3604 — vllm: Mehrere Schwachstellen</title>
    <updated>2026-10-09T06:33:17.653804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in vllm ausnutzen, um Informationen offenzulegen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3604"/>
  </entry>
</feed>
