Skip to content
vLLMPYSEC-2026-4008

vLLM: attacker could allocate unbounded memory

UnratedCVE-2026-94626 · Published Sep 21, 2026 · updated Sep 30, 2026

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.

Source advisory

Affected versions

PackageAffectedFixed in
vllm
PyPI
< 0.30.00.30.0
Details and references

More vLLM advisories

All vLLM
Advisory
vLLM: denial of service
High7.5Sep 21
vLLM: denial of service
High7.5Sep 21
vLLM: resource exhaustion
Medium5.3Sep 21
vLLM: denial of service
UnratedSep 21
vLLM through 0.29.0 fails to properly validate bad_words token indices against...
Medium4.3Sep 19
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead...
Medium5.3Sep 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.