Package
lmcache-cuda-12.8
Component
vllm
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-57173 (GHSA-hcwq-8wjf-3gcr) is an unauthenticated audio decompression-bomb denial of service in the vLLM chat completions endpoint, fixed upstream in vLLM 0.24.0 (https://github.com/vllm-project/vllm/pull/45908). This package pins vllm 0.19.1, the last release installable on a CUDA 12.8 stack: every vLLM release from 0.20.0 onward pins torch 2.11.0 (0.27.0+ torch 2.13.0), whose PyPI wheels require CUDA 13 bindings, so resolution against cuda-bindings~=12.8 is unsatisfiable. The vulnerable code (audio decoding without a duration limit in the chat path) is present in 0.19.1. Remediated in lmcache-cuda-13.0, which tracks current vLLM.
Status