CVE-2026-94624: vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur
Summary
vLLM (a system for running large language models) versions up to 0.29.0 have a denial of service vulnerability (a bug that lets attackers crash the system) in its P2P KV offloading feature (a method where the system transfers memory data between computers in a peer-to-peer network). Attackers can provide fake network addresses that cause the system to create broken connections that waste memory resources until the system crashes and stops responding to user requests.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
network
low
none
none
September 21, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-94624
First tracked: September 21, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 95%