CVE-2025-46570
Last modified
CVE-2025-46570 is a low-severity vulnerability rated 2.6/10 on the CVSS scale. vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). These timing differences caused by matching chunks are significant enough to be recognized and exploited. This issue has been patched in version 0.9.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vllm | Vllm | < 0.9.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-46570?
How severe is CVE-2025-46570?
How do I fix CVE-2025-46570?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46565Vite is a frontend tooling framework for javascript. Prior t…5.3
- CVE-2025-46566DataEase is an open-source BI tool alternative to Tableau. P…9.8
- CVE-2025-46567LLama Factory enables fine-tuning of large language models. …7.8
- CVE-2025-46568Stirling-PDF is a locally hosted web application that allows…7.5
- CVE-2025-46569Open Policy Agent (OPA) is an open source, general-purpose p…7.4
- CVE-2025-4657A buffer overflow vulnerability was reported in the Lenovo P…8.4
- CVE-2025-46571Open WebUI is a self-hosted artificial intelligence platform…5.4
- CVE-2025-46572passport-wsfed-saml2 provides passport strategy for both WS-…9.3
- CVE-2025-46573passport-wsfed-saml2 provides passport strategy for both WS-…8.6
- CVE-2025-46574There is an information disclosure vulnerability in the Gold…5.3
- CVE-2025-46575There is an information disclosure vulnerability in the Gold…7.5
- CVE-2025-46576There is a Permission Management and Access Control vulnerab…6.5
Are you affected by CVE-2025-46570?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
