Resource Exhaustion Vulnerability in vLLM by vLLM Project
CVE-2026-94625

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94625?

vLLM, up to version 0.29.0, is susceptible to a resource exhaustion flaw within the MooncakeConnector. This vulnerability allows attackers to submit rejected prefill requests that result in ownerless transfer placeholders, which are never reclaimed. Consequently, this leads to the exhaustion of sender task pools, severely delaying legitimate requests by as much as 480 seconds, while the system continues to report health checks as successful. Awareness and mitigation of this issue are crucial for maintaining the performance and reliability of systems utilizing vLLM.

Affected Version(s)

vllm 0 <= 0.29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mingkai Yu
Jiapeng Li
Jiajia Liu
.