PT-2026-96317 · Vllm · Vllm

·

CVE-2026-94627

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.29.1
Description The Mooncake connector fails to properly manage GPU KV cache block ownership during prefill/decode disaggregated deployments when concurrent child requests share a single transfer ID. An attacker can cause GPU memory exhaustion by submitting completion requests containing multiple prompts. This action leads to the accumulation of orphaned KV cache blocks—memory blocks that are no longer associated with an active request but are not released—which persist until the process is restarted, eventually blocking legitimate requests from executing.
Recommendations Update vLLM to a version newer than 0.29.0.

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94627

Affected Products

Vllm