vLLMPYSEC-2026-4006
vLLM: denial of service
High7.5CVE-2026-94624 · Published Sep 21, 2026 · updated Sep 30, 2026
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.30.0 | 0.30.0 |
Changes since it was listed
| Date | Change |
|---|---|
| Oct 2 | Severity: Unrated to High |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-94624
- github.com/vllm-project/vllm/blob/v0.29.0/vllm/v1/kv_offload/tiering/p2p/control/zmq.py#L240-L260
- github.com/vllm-project/vllm/blob/v0.29.0/vllm/v1/kv_offload/tiering/p2p/manager.py#L667-L677
- www.vulncheck.com/advisories/vllm-through-0.29.0-denial-of-service-via-unbounded-p2p-kv-offloading-sessions
- github.com/vllm-project/vllm/pull/51504
- github.com/vllm-project/vllm
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 21 | vLLM: denial of service | High7.5 | 0.30.0 |
| Sep 21 | vLLM: resource exhaustion | Medium5.3 | 0.30.0 |
| Sep 21 | vLLM: attacker could allocate unbounded memory | Unrated | 0.30.0 |
| Sep 21 | vLLM: denial of service | Unrated | 0.30.0 |
| Sep 19 | vLLM through 0.29.0 fails to properly validate bad_words token indices against... | Medium4.3 | 0.30.0 |
| Sep 18 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead... | Medium5.3 | 0.29.0 |