OCTOBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-94627

HIGH · CVSS 7.5 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-01

CyberRota Analysis

AI-Generated

The vLLM Mooncake connector versions prior to 0.29.0 are vulnerable due to improper management of GPU KV cache block ownership, which can lead to GPU memory exhaustion when multiple child requests share a single transfer ID. This vulnerability allows attackers to submit numerous completion requests, causing orphaned KV cache blocks to accumulate and ultimately blocking legitimate requests from being processed. Organizations utilizing the affected versions, particularly those relying on GPU resources for concurrent processing, should prioritize addressing this issue to maintain service availability and performance.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94627
Severity
HIGH
CVSS
7.5
EPSS
0.63%

Original NVD Description

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing legitimate requests from executing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)