The LMVD-ID is an internal research identifier, not an official CVE identifier.
Shared relay credentials weaken prompt-cache isolation
API gateways can pool distinct customers into one upstream cache identity. The authors observe cross-customer cache reuse in five deliberately pooled gateway configurations through two provider interfaces.
Paper-evaluated models
No paper-evaluated models are recorded for this entry.
Description
API gateways can pool distinct customers into one upstream cache identity. The authors observe cross-customer cache reuse in five deliberately pooled gateway configurations through two provider interfaces.
Examples
See the primary study (opens in a new tab).
Impact
Cache feedback can disclose prior use of known content. Results depend on the final route, identity mapping and observation window. Relay model labels do not establish a defect in the underlying foundation model or every gateway deployment.
Affected Systems
- Evaluated configurations of NewAPI, uni-api, MetaAPI, LiteLLM and Sub2API.
Mitigation Steps
- Preserve authenticated tenant identity through retries, fallbacks and nested relays.
- Require provider-enforced cache isolation and fail closed when unavailable.
- Verify isolation in controlled tenant environments after routing changes.
Evidence
Research context and confidence
- Evidence and verification
- Paper-reported; independent reproduction is not documented.
- Primary source plus a dedicated evidence section.
- Severity
- Not rated by this catalog.
- Source and publication type
- arXiv · Research preprint.
- Peer-review status is not provided by this source.
- Author and publication status
- Author metadata is not stored; see the primary paper.
- Threat model and attacker access
- Not explicitly classified; consult the primary paper..
- Related deployment categories
- Model APIs
- Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
- Affected systems
- Evaluated configurations of NewAPI, uni-api, MetaAPI, LiteLLM and Sub2API.
Research Paper
KeyPooling: Measuring Where LLM API Relay Paths Collapse Prompt Cache Isolation
Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.
View PaperRelated research
- Historical reasoning-envelope isolation failures
Published August 10, 2026 · infrastructure-layer, extraction, prompt-leaking
- Incomplete MCP Tool-Call Attack Detection
Published July 28, 2026 · application-layer, infrastructure-layer, prompt-layer
- Agent Lifecycle Compound Threats
Published March 1, 2026 · application-layer, infrastructure-layer, prompt-layer