Vllm · Vllm · CVE-2026-92220
**Name of the Vulnerable Software and Affected Versions**
vLLM versions 0.26.0 through 0.27.0
**Description**
A resource consumption issue exists in the MoRIIO Acknowledgement Handler component within the file vllm/distributed/kv transfer/kv connector/v1/moriio/moriio connector.py. A remote attacker can trigger this by manipulating the `request id` or `kv transfer params` arguments. The affected functions include `MoRIIOConnectorScheduler.request finished()`, `MoRIIOConnectorWorker.get finished()`, and `MoRIIOWrapper. handle release message()`.
**Recommendations**
As a temporary mitigation, restrict access to the `MoRIIOConnectorScheduler.request finished()`, `MoRIIOConnectorWorker.get finished()`, and `MoRIIOWrapper. handle release message()` functions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.