CVE-2025-46570
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
2.6
LOW
CVSS 3.1
EPSS 0.25%
描述
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). These timing differences caused by matching chunks are significant enough to be recognized and exploited. This issue has been patched in version 0.9.0.
如何修補 CVE-2025-46570
要修補 CVE-2025-46570,請將受影響套件升級到下列已修補版本。
- —升級至 0.9.0 或更新版本
- —升級至 77073c77bc2006eb80ea6d5128f076f5e6c6f54f 或更新版本
CVE-2025-46570 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.9.0
- from 0, < 77073c77bc2006eb80ea6d5128f076f5e6c6f54f | from 0, < 0.9.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW2.6 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |