Resource Exhaustion Vulnerability in vLLM by vLLM Project
CVE-2026-94625
6.9MEDIUM
What is CVE-2026-94625?
vLLM, up to version 0.29.0, is susceptible to a resource exhaustion flaw within the MooncakeConnector. This vulnerability allows attackers to submit rejected prefill requests that result in ownerless transfer placeholders, which are never reclaimed. Consequently, this leads to the exhaustion of sender task pools, severely delaying legitimate requests by as much as 480 seconds, while the system continues to report health checks as successful. Awareness and mitigation of this issue are crucial for maintaining the performance and reliability of systems utilizing vLLM.
Affected Version(s)
vllm 0 <= 0.29.0
