GHSA-3hh9-752g-5g22

Suggest an improvement
Source
https://github.com/advisories/GHSA-3hh9-752g-5g22
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3hh9-752g-5g22/GHSA-3hh9-752g-5g22.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3hh9-752g-5g22
Aliases
Downstream
MINI (2)
Published
2026-06-04T18:30:31Z
Modified
2026-07-23T15:11:28Z
Severity
  • 3.6 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
LMCache: 16-bit multimodal hash collision can poison KV cache entries
Details

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cwe_ids":  [
        "CWE-327"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-15T22:10:24Z",
    "nvd_published_at":  "2026-06-04T16:16:32Z",
    "severity":  "LOW"
}
References

Affected packages

PyPI / lmcache

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.4.6

Affected versions

0.*
0.3.0
0.3.1
0.3.1.post1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.9
0.3.9.post1
0.3.9.post2
0.3.10
0.3.10.post1
0.3.10.post2
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-3hh9-752g-5g22/GHSA-3hh9-752g-5g22.json"