AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-4qjh-9fv9-r85r: Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

OSV AI package advisories · observation · May 28, 2025 · UTC

This issue arises from the prefix caching mechanism, which may expose the system to a timing side-channel attack. ## Description When a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (Time to First Token). Our tests revealed that the timing differences caused by matching chunks are significant enough to be recognized and exploited. For instance, if the victim has submitted a sensitive prompt or if a valuable system prompt has been cached, an attacker sharing the same backend could attempt to g

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.