vLLMPYSEC-2026-4005
vLLM: denial of service
High7.5CVE-2026-94623 · Published Sep 21, 2026 · updated Sep 30, 2026
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.30.0 | 0.30.0 |
Changes since it was listed
| Date | Change |
|---|---|
| Oct 2 | Severity: Unrated to High |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-94623
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 21 | vLLM: denial of service | High7.5 | 0.30.0 |
| Sep 21 | vLLM: resource exhaustion | Medium5.3 | 0.30.0 |
| Sep 21 | vLLM: attacker could allocate unbounded memory | Unrated | 0.30.0 |
| Sep 21 | vLLM: denial of service | Unrated | 0.30.0 |
| Sep 19 | vLLM through 0.29.0 fails to properly validate bad_words token indices against... | Medium4.3 | 0.30.0 |
| Sep 18 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead... | Medium5.3 | 0.29.0 |