CyberRota Analysis
AI-GeneratedvLLM versions up to 0.29.0 are susceptible to a resource exhaustion vulnerability in the MooncakeConnector, where rejected prefill requests lead to the creation of unreclaimed transfer placeholders. This can result in significant delays for valid requests, potentially extending up to 480 seconds, while the system falsely reports operational health. Organizations utilizing vLLM should prioritize addressing this vulnerability to mitigate the risk of service disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.
Related CVEs
Other vulnerabilities affecting the same vendor(s)