PT-2026-96315 · Vllm · Vllm

·

CVE-2026-94625

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.29.1
Description A resource exhaustion issue exists in the MooncakeConnector component. Rejected prefill requests generate ownerless transfer placeholders that are not reclaimed by the system. An attacker can exploit this by sending rejected requests to exhaust sender task pools, which results in valid requests being delayed by up to 480 seconds. During this state, health checks continue to report success, masking the issue.
Recommendations Update vLLM to a version newer than 0.29.0.

Exploit

Fix

DoS

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94625
PYSEC-2026-4007

Affected Products

Vllm