OCTOBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-94625

MEDIUM · CVSS 5.3 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-01

CyberRota Analysis

AI-Generated

vLLM versions up to 0.29.0 are susceptible to a resource exhaustion vulnerability in the MooncakeConnector, where rejected prefill requests lead to the creation of unreclaimed transfer placeholders. This can result in significant delays for valid requests, potentially extending up to 480 seconds, while the system falsely reports operational health. Organizations utilizing vLLM should prioritize addressing this vulnerability to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94625
Severity
MEDIUM
CVSS
5.3
EPSS
0.52%

Original NVD Description

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.

Related CVEs

Other vulnerabilities affecting the same vendor(s)