PT-2026-96312 · Vllm · Vllm
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.1
Description
A denial of service issue exists in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. An attacker can send requests containing incomplete
kv transfer params dictionary entries, which triggers an uncaught KeyError during EngineCore scheduling. This results in the termination of the decode engine, causing all routed requests to fail until the system is manually restarted.Recommendations
Update vLLM to a version newer than 0.29.0.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm