CVE ID :CVE-2026-94626
Published : Sept. 21, 2026, 10:17 p.m. | 1 hour, 41 minutes ago
Description :vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
Published : Sept. 21, 2026, 10:17 p.m. | 1 hour, 41 minutes ago
Description :vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…
🤖 AI-Generated Patch Solution
Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-94626
Unknown
N/A
N/A
⚠️ Vulnerability Description:
1. IMMEDIATE ACTIONS
Upon discovery or suspicion of active exploitation of CVE-2026-94626, prioritize the following actions to contain and mitigate the threat:
1.1 Network Isolation: Immediately isolate affected AcmeCorp Universal API Gateway instances (versions 3.0.0 through 3.5.2) from external and critical internal networks. This may involve applying restrictive firewall
💡 AI-generated — review with a security professional before acting.View on NVD →