Denial of Service Vulnerability in vLLM by vllm-project
CVE-2026-92220

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92220?

A vulnerability exists in the vLLM project, specifically in the MoRIIO Acknowledgement Handler within the vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py file. This flaw resides in the functions MoRIIOConnectorScheduler.request_finished, MoRIIOConnectorWorker.get_finished, and MoRIIOWrapper._handle_release_message. An attacker can manipulate the request_id and kv_transfer_params arguments to cause significant resource consumption, potentially leading to service disruption. This issue can be exploited remotely, enabling attackers to execute Denial of Service (DoS) attacks if unaddressed. The vllm-project was notified of this vulnerability via a pull request but has yet to release a fix.

Affected Version(s)

vLLM 0.26.0

vLLM 0.27.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JPengLi (VulDB User)
VulDB CNA Team
.