rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-94623

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha…

Description

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
8.7
EPSS

← All CVEs