Skip to content
vLLMPYSEC-2026-4004

vLLM: denial of service

UnratedCVE-2026-94622 · Published Sep 21, 2026 · updated Sep 30, 2026

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart.

Source advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
< 0.30.00.30.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
no source yet
Also known as
CVE-2026-94622

More vLLM advisories

All vLLM
Advisory
vLLM: denial of service
High7.5Sep 21
vLLM: denial of service
High7.5Sep 21
vLLM: resource exhaustion
Medium5.3Sep 21
vLLM: attacker could allocate unbounded memory
UnratedSep 21
vLLM through 0.29.0 fails to properly validate bad_words token indices against...
Medium4.3Sep 19
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead...
Medium5.3Sep 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.