{"data":{"id":"364fea1a-e4f6-467b-9597-7a5f357886fc","title":"CVE-2026-92220: A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_","summary":"A vulnerability was found in vLLM versions 0.26.0 and 0.27.0 in the MoRIIO (a distributed key-value transfer component) acknowledgement handler that allows remote attackers to manipulate certain arguments and cause excessive resource consumption (a denial-of-service attack where a system runs out of memory or CPU). The developers were notified through a pull request but have not yet responded or released a fix.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92220","publishedAt":"2026-09-16T03:17:00.407Z","cveId":"CVE-2026-92220","cweIds":["CWE-400","CWE-404"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM","vllm-project"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-16T03:17:00.407Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}