PT-2026-96315 · Vllm · Vllm
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.1
Description
A resource exhaustion issue exists in the
MooncakeConnector component. Rejected prefill requests generate ownerless transfer placeholders that are not reclaimed by the system. An attacker can exploit this by sending rejected requests to exhaust sender task pools, which results in valid requests being delayed by up to 480 seconds. During this state, health checks continue to report success, masking the issue.Recommendations
Update vLLM to a version newer than 0.29.0.
Exploit
Fix
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm