CVE-2026-94627
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:16
- Zuletzt bearbeitet 29.09.2026 12:46:29
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitt...
CVE-2026-94626
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:15
- Zuletzt bearbeitet 29.09.2026 12:46:53
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregate...
CVE-2026-94625
- EPSS 0.3%
- Veröffentlicht 21.09.2026 22:04:14
- Zuletzt bearbeitet 29.09.2026 12:47:01
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, ...
CVE-2026-94624
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:13
- Zuletzt bearbeitet 29.09.2026 12:47:10
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_...
CVE-2026-94623
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:12
- Zuletzt bearbeitet 29.09.2026 12:47:21
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Att...
CVE-2026-94622
- EPSS 0.45%
- Veröffentlicht 21.09.2026 22:04:10
- Zuletzt bearbeitet 29.09.2026 12:47:29
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigge...
CVE-2026-93989
- EPSS 0.2%
- Veröffentlicht 19.09.2026 22:58:10
- Zuletzt bearbeitet 28.09.2026 18:38:31
vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent re...
CVE-2026-93841
- EPSS 0.24%
- Veröffentlicht 18.09.2026 19:06:06
- Zuletzt bearbeitet 28.09.2026 18:35:40
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio reque...
CVE-2026-93840
- EPSS 0.25%
- Veröffentlicht 18.09.2026 19:06:06
- Zuletzt bearbeitet 28.09.2026 18:36:00
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing Log...
CVE-2026-93592
- EPSS 0.38%
- Veröffentlicht 18.09.2026 13:20:05
- Zuletzt bearbeitet 28.09.2026 18:37:06
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID...