CVE-2026-92220
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Summary
A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a manipulation of the argument request_id/kv_transfer_params results in resource consumption. It is possible to initiate the attack remotely. The project was informed of the problem early through a pull request but has not reacted yet.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vLLM | 0.26.0 | affected |
| vllm-project | vLLM | 0.27.0 | affected |
Weaknesses
- CWE-400: Resource Consumption
- CWE-404: Denial of Service
References
- https://vuldb.com/vuln/404470
- https://vuldb.com/vuln/404470/cti
- https://vuldb.com/cve/CVE-2026-92220
- https://vuldb.com/submit/934149
- https://github.com/vllm-project/vllm/pull/50674
- https://github.com/vllm-project/vllm/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.