PT-2026-96314 · Vllm · Vllm

·

CVE-2026-94624

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.29.1
Description A denial of service issue exists in P2P KV offloading when the OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. An attacker can provide arbitrary remote host and port values via the kv transfer params parameter to create unreachable peer sessions. These sessions retain ZeroMQ sockets until the context quota is exhausted, leading to an uncaught ZMQError that crashes EngineCore and halts all inference operations.
Recommendations Update vLLM to a version later than 0.29.0.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94624
PYSEC-2026-4006

Affected Products

Vllm