vLLMPYSEC-2026-4007
vLLM: resource exhaustion
Medium5.3CVE-2026-94625 · Published Sep 21, 2026 · updated Sep 30, 2026
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vllm PyPI | < 0.30.0 | 0.30.0 |
Changes since it was listed
| Date | Change |
|---|---|
| Oct 2 | Severity: Unrated to Medium |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- NVD
- Also known as
- CVE-2026-94625
- github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/mooncake/mooncake_connector.py#L1234-L1242
- www.vulncheck.com/advisories/vllm-through-0.29.0-resource-exhaustion-via-ownerless-mooncake-transfer-placeholders
- github.com/vllm-project/vllm/pull/51236
- github.com/vllm-project/vllm
More vLLM advisories
All vLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 21 | vLLM: denial of service | High7.5 | 0.30.0 |
| Sep 21 | vLLM: denial of service | High7.5 | 0.30.0 |
| Sep 21 | vLLM: attacker could allocate unbounded memory | Unrated | 0.30.0 |
| Sep 21 | vLLM: denial of service | Unrated | 0.30.0 |
| Sep 19 | vLLM through 0.29.0 fails to properly validate bad_words token indices against... | Medium4.3 | 0.30.0 |
| Sep 18 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead... | Medium5.3 | 0.29.0 |