{"data":{"id":"7820d778-0192-47eb-a375-35f07e245acc","title":"CVE-2026-94625: vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr","summary":"vLLM (a language model serving framework) versions up to 0.29.0 have a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests (requests to prepare the AI model before full processing) leave behind unused data placeholders that never get cleaned up. An attacker can exploit this by sending many rejected requests to clog the system's worker pools, making legitimate requests wait up to 480 seconds while the system falsely reports it's healthy.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94625","publishedAt":"2026-09-21T22:17:01.433Z","cveId":"CVE-2026-94625","cweIds":["CWE-772"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T22:17:01.433Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}