Shared relay credentials weaken prompt-cache isolation
API gateways can pool distinct customers into one upstream cache identity. The authors observe cross-customer cache reuse in five deliberately pooled gateway configurations through two provider interfaces.
- Published
- Analyzed
Cite & share
Citation metadata is maintained by the primary source and may reflect a later revision.
Paper-evaluated models
No paper-evaluated models are recorded for this entry.
On this page
Description
API gateways can pool distinct customers into one upstream cache identity. The authors observe cross-customer cache reuse in five deliberately pooled gateway configurations through two provider interfaces.
Examples
See the primary study (opens in a new tab).
Impact
Cache feedback can disclose prior use of known content. Results depend on the final route, identity mapping and observation window. Relay model labels do not establish a defect in the underlying foundation model or every gateway deployment.
Affected Systems
- Evaluated configurations of NewAPI, uni-api, MetaAPI, LiteLLM and Sub2API.
Mitigation Steps
- Preserve authenticated tenant identity through retries, fallbacks and nested relays.
- Require provider-enforced cache isolation and fail closed when unavailable.
- Verify isolation in controlled tenant environments after routing changes.
Evidence
Research context and provenance
- Research topics
- Catalog identifier
- LMVD-f930fc6d
- Internal research identifier, not an official CVE identifier.
- Evidence and verification
- Paper-reported; independent reproduction is not documented.
- Primary source plus a dedicated evidence section.
- Severity
- Not rated by this catalog.
- Source and publication type
- arXiv · Research preprint.
- Peer-review status is not provided by this source.
- Author and publication status
- Author metadata is not stored; see the primary paper.
- Threat model and attacker access
- Not explicitly classified; consult the primary paper.
- Related deployment categories
- Model APIs
- Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
- Affected systems
- Evaluated configurations of NewAPI, uni-api, MetaAPI, LiteLLM and Sub2API.
Research Paper
KeyPooling: Measuring Where LLM API Relay Paths Collapse Prompt Cache Isolation
Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.
View PaperRelated research
- Historical reasoning-envelope isolation failures
Published August 10, 2026 · Infrastructure, Extraction, Prompt leaking
- Incomplete MCP Tool-Call Attack Detection
Published July 28, 2026 · Application layer, Infrastructure, Prompt layer
- Autonomous Agent Tool RCE
Published March 13, 2026 · Application layer, Infrastructure, Prompt layer