Use of a Broken or Risky Cryptographic Algorithm Affecting vllm-cu130 package, versions <0.23.0-r0


Severity

Recommended
0.0
low
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.08% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-VLLMCU130-17997207
  • published17 Jul 2026
  • disclosed4 Jun 2026

Introduced: 4 Jun 2026

CVE-2026-10813  (opens in a new tab)
CWE-327  (opens in a new tab)
CWE-328  (opens in a new tab)

How to fix?

Upgrade Minimos:latest vllm-cu130 to version 0.23.0-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream vllm-cu130 package and not the vllm-cu130 package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

CVSS Base Scores

version 3.1