CVE-2026-94623: vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha
Summary
vLLM versions up to 0.29.0 have a denial of service vulnerability in its NIXL connector's prefix caching (a feature that reuses parts of previously processed text to speed up responses) that doesn't properly check block counts when handling multiple prompts of different lengths in certain deployment setups. An attacker can crash the decode worker (the part that generates responses) by sending specially crafted requests, forcing a restart to restore service.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
network
low
none
none
September 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-94623
First tracked: September 21, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 95%