Skip to content
vLLMPYSEC-2026-4005

vLLM: denial of service

High7.5CVE-2026-94623 · Published Sep 21, 2026 · updated Sep 30, 2026

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.

Source advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
< 0.30.00.30.0

Changes since it was listed

DateChange
Oct 2Severity: Unrated to High
Details and references

More vLLM advisories

All vLLM
Advisory
vLLM: denial of service
High7.5Sep 21
vLLM: resource exhaustion
Medium5.3Sep 21
vLLM: attacker could allocate unbounded memory
UnratedSep 21
vLLM: denial of service
UnratedSep 21
vLLM through 0.29.0 fails to properly validate bad_words token indices against...
Medium4.3Sep 19
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead...
Medium5.3Sep 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.