Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference. | |
| Title | vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions | |
| First Time appeared |
Vllm
Vllm vllm |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm
Vllm vllm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T22:04:13.172Z
Reserved: 2026-09-21T21:42:26.965Z
Link: CVE-2026-94624
No data.
Status : Received
Published: 2026-09-21T22:17:01.280
Modified: 2026-09-21T22:17:01.280
Link: CVE-2026-94624
No data.
OpenCVE Enrichment
No data.