OCTOBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-94624

HIGH · CVSS 7.5 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-01

CyberRota Analysis

AI-Generated

A denial of service vulnerability exists in vLLM versions up to 0.29.0, specifically affecting the P2P KV offloading feature when configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can exploit this flaw by providing arbitrary remote host and port values, leading to unreachable peer sessions that exhaust the context quota and crash the EngineCore, halting all inference processes. Organizations utilizing vLLM in their systems should prioritize addressing this vulnerability to maintain service availability and prevent potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94624
Severity
HIGH
CVSS
7.5
EPSS
0.63%

Original NVD Description

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.

Related CVEs

Other vulnerabilities affecting the same vendor(s)