Denial of Service Vulnerability in vLLM by vllm-project
CVE-2026-92220
6.9MEDIUM
What is CVE-2026-92220?
A vulnerability exists in the vLLM project, specifically in the MoRIIO Acknowledgement Handler within the vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py file. This flaw resides in the functions MoRIIOConnectorScheduler.request_finished, MoRIIOConnectorWorker.get_finished, and MoRIIOWrapper._handle_release_message. An attacker can manipulate the request_id and kv_transfer_params arguments to cause significant resource consumption, potentially leading to service disruption. This issue can be exploited remotely, enabling attackers to execute Denial of Service (DoS) attacks if unaddressed. The vllm-project was notified of this vulnerability via a pull request but has yet to release a fix.
Affected Version(s)
vLLM 0.26.0
vLLM 0.27.0
