{"data":{"id":"a2b5af22-102b-4ed9-aa26-ab47e76bc976","title":"CVE-2026-94627: vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child reque","summary":"A vulnerability in vLLM Mooncake connector (a component that helps distribute AI model processing across systems) through version 0.29.0 fails to properly track ownership of GPU KV cache blocks (temporary storage on graphics processors for speeding up AI responses) when multiple child requests share the same transfer ID. Attackers can exploit this by sending completion requests with multiple prompts, causing orphaned cache blocks to build up until the system restarts, eventually blocking legitimate user requests from running.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94627","publishedAt":"2026-09-21T22:17:01.740Z","cveId":"CVE-2026-94627","cweIds":["CWE-401"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["vLLM","Mooncake"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T22:17:01.740Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}