CVE-2026-94625: vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr
Summary
vLLM (a language model serving framework) versions up to 0.29.0 have a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests (requests to prepare the AI model before full processing) leave behind unused data placeholders that never get cleaned up. An attacker can exploit this by sending many rejected requests to clog the system's worker pools, making legitimate requests wait up to 480 seconds while the system falsely reports it's healthy.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
network
low
none
none
September 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-94625
First tracked: September 21, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 95%