CVE-2026-94623: Reachable Assertion in vllm-project vllm
vLLM versions up to 0.29.0 contain a denial of service vulnerability in the NIXL connector's prefix caching implementation. This flaw allows attackers to cause an assertion failure by submitting multi-prompt completion requests with varying prompt lengths, leading to termination of the decode worker. The affected worker remains unavailable until manually restarted, disrupting service availability.
AI Analysis
Technical Summary
CVE-2026-94623 is a denial of service vulnerability in vLLM through version 0.29.0. The issue resides in the NIXL connector's prefix caching mechanism, which does not properly validate block counts when handling multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can exploit this by sending completion requests containing multiple prompts of different lengths, triggering an assertion failure in the NixlBaseConnectorWorker._apply_prefix_caching function. This causes the decode worker process to terminate unexpectedly and become unavailable until a manual restart is performed.
Potential Impact
Successful exploitation results in denial of service by crashing the decode worker component of vLLM, rendering it unavailable until manually restarted. This disrupts the availability of the service relying on the decode worker, potentially impacting dependent applications or users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid sending multi-prompt completion requests with varying prompt lengths in prefill/decode disaggregated deployments or implement monitoring to detect and restart the decode worker if it terminates unexpectedly.
CVE-2026-94623: Reachable Assertion in vllm-project vllm
Description
vLLM versions up to 0.29.0 contain a denial of service vulnerability in the NIXL connector's prefix caching implementation. This flaw allows attackers to cause an assertion failure by submitting multi-prompt completion requests with varying prompt lengths, leading to termination of the decode worker. The affected worker remains unavailable until manually restarted, disrupting service availability.
CVSS v4.0
Score 8.7high
Affected software
vllm-project
vllm
pkg:github/vllm-project/vllmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94623 is a denial of service vulnerability in vLLM through version 0.29.0. The issue resides in the NIXL connector's prefix caching mechanism, which does not properly validate block counts when handling multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can exploit this by sending completion requests containing multiple prompts of different lengths, triggering an assertion failure in the NixlBaseConnectorWorker._apply_prefix_caching function. This causes the decode worker process to terminate unexpectedly and become unavailable until a manual restart is performed.
Potential Impact
Successful exploitation results in denial of service by crashing the decode worker component of vLLM, rendering it unavailable until manually restarted. This disrupts the availability of the service relying on the decode worker, potentially impacting dependent applications or users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid sending multi-prompt completion requests with varying prompt lengths in prefill/decode disaggregated deployments or implement monitoring to detect and restart the decode worker if it terminates unexpectedly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-21T21:42:25.636Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab1acdf55bf5e2cf58d35c1
Added to database: 09/21/2026, 22:17:03 UTC
Last enriched: 09/21/2026, 22:31:39 UTC
Last updated: 09/21/2026, 22:56:45 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.