Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vllm-project
Vllm-project vllm |
|
| Vendors & Products |
Vllm-project
Vllm-project vllm |
Mon, 21 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference. | |
| Title | vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions | |
| First Time appeared |
Vllm
Vllm vllm |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm
Vllm vllm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T13:26:57.950Z
Reserved: 2026-09-21T21:42:26.965Z
Link: CVE-2026-94624
Updated: 2026-09-22T13:26:35.772Z
Status : Awaiting Analysis
Published: 2026-09-21T22:17:01.280
Modified: 2026-09-22T20:25:55.870
Link: CVE-2026-94624
No data.
OpenCVE Enrichment
Updated: 2026-09-21T23:30:18Z
-
CWE-770
Allocation of Resources Without Limits or Throttling