VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-94625

CVE-2026-94625: vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr

Published Sep 21, 2026 CVSS 6.9

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.

Affected AI Products

vllm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.