{"id":"CVE-2026-94625","published":"2026-09-21T22:17:01.433","lastModified":"2026-09-21T22:17:01.433","description":"vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwes":["CWE-772"],"vendors":[],"products":[],"references":[{"url":"https://github.com/vllm-project/vllm","tags":[]},{"url":"https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/mooncake/mooncake_connector.py#L1234-L1242","tags":[]},{"url":"https://github.com/vllm-project/vllm/pull/51236","tags":[]},{"url":"https://www.vulncheck.com/advisories/vllm-through-0.29.0-resource-exhaustion-via-ownerless-mooncake-transfer-placeholders","tags":[]}],"exploitRefs":[{"url":"https://github.com/vllm-project/vllm","tags":[]},{"url":"https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/mooncake/mooncake_connector.py#L1234-L1242","tags":[]},{"url":"https://github.com/vllm-project/vllm/pull/51236","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows attackers to send rejected prefill requests that create ownerless transfer placeholders, leading to resource exhaustion and delayed processing of valid requests.","exploitability":"Exploitation requires sending specific rejected requests; it is moderately difficult due to the need for understanding the system's request handling mechanisms.","blast_radius":"If exploited, this could significantly impact service availability by delaying or blocking valid requests, affecting user experience and potentially leading to operational disruptions.","remediation":"Update vLLM to version 0.29.1 or later, which addresses this vulnerability according to the project's security updates.","tags":["resource-exhaustion","delay","vulnerability","update"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:29:31.515Z"}}