PT-2026-96316 · Vllm · Vllm

·

CVE-2026-94626

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.29.1
Description OpenAI-compatible completion endpoints fail to validate the tp size parameter within kv transfer params. In prefill/decode disaggregated deployments, an attacker can provide arbitrary values for tp size to allocate unbounded memory, which can exhaust system resources and trigger a kernel OOM-kill (Out-Of-Memory kill, a process where the operating system terminates a process to free up memory) of the decode worker process.
Recommendations Update vLLM to version 0.29.1 or later. Avoid using the tp size parameter in the kv transfer params of OpenAI-compatible completion endpoints until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94626
PYSEC-2026-4008

Affected Products

Vllm