{"data":{"id":"1dbed036-ee1b-4c66-886a-c7d3f0cda4fb","title":"CVE-2026-94624: vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur","summary":"vLLM (a system for running large language models) versions up to 0.29.0 have a denial of service vulnerability (a bug that lets attackers crash the system) in its P2P KV offloading feature (a method where the system transfers memory data between computers in a peer-to-peer network). Attackers can provide fake network addresses that cause the system to create broken connections that waste memory resources until the system crashes and stops responding to user requests.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94624","publishedAt":"2026-09-21T22:17:01.280Z","cveId":"CVE-2026-94624","cweIds":["CWE-770"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T22:17:01.280Z","capecIds":["CAPEC-130"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}