Skip to content

Menu
  • Home
Menu

CVE-2026-94626 – vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size

Posted on September 22, 2026
CVE ID :CVE-2026-94626

Published : Sept. 21, 2026, 10:17 p.m. | 1 hour, 41 minutes ago

Description :vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-94626

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

Upon discovery or suspicion of active exploitation of CVE-2026-94626, prioritize the following actions to contain and mitigate the threat:

1.1 Network Isolation: Immediately isolate affected AcmeCorp Universal API Gateway instances (versions 3.0.0 through 3.5.2) from external and critical internal networks. This may involve applying restrictive firewall

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 3

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme