CVE-2025-25183
CVSS 3.1 Score 2.6 of 10 (low)
Details
Summary
CVE-2025-25183 is a vulnerability affecting the vLLM inference and serving engine for LLMs. Maliciously constructed statements can lead to hash collisions in the engine's prefix caching feature, causing cache reuse and unintended behavior. This issue becomes more feasible due to a change in Python's hash() function behavior in version 3.12. attackers could exploit hash collisions and use cache generated with different content, potentially interfering with subsequent responses. The impact of this collision is significant, as it could lead to unexpected system behavior. Users are advised to upgrade to version 0.7.2 to mitigate this vulnerability, and there are currently no known workarounds.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.