CVE-2026-94626: Memory Allocation with Excessive Size Value in vllm-project vllm
vLLM versions up to 0.29.0 contain a vulnerability where the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints is not validated. This allows attackers to request memory allocations of arbitrary size, potentially exhausting system memory and causing the decode worker process to be terminated by the kernel's out-of-memory (OOM) killer.
AI Analysis
Technical Summary
CVE-2026-94626 is a memory allocation vulnerability in vLLM through version 0.29.0. The software fails to validate the tp_size parameter in the kv_transfer_params function used on OpenAI-compatible completion endpoints. Attackers can supply excessively large tp_size values in prefill/decode disaggregated deployments, leading to unbounded memory allocation requests. This can exhaust available memory resources and trigger the kernel's OOM-killer to terminate the decode worker process, resulting in denial of service.
Potential Impact
Successful exploitation allows an unauthenticated attacker to cause a denial of service by exhausting system memory, leading to the termination of the decode worker process. This disrupts normal operation of the vLLM service but does not indicate direct code execution or data compromise based on the provided information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoints to trusted users and monitor resource usage to detect abnormal memory consumption patterns.
CVE-2026-94626: Memory Allocation with Excessive Size Value in vllm-project vllm
Description
vLLM versions up to 0.29.0 contain a vulnerability where the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints is not validated. This allows attackers to request memory allocations of arbitrary size, potentially exhausting system memory and causing the decode worker process to be terminated by the kernel's out-of-memory (OOM) killer.
CVSS v4.0
Score 8.7high
Affected software
vllm-project
vllm
pkg:github/vllm-project/vllmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94626 is a memory allocation vulnerability in vLLM through version 0.29.0. The software fails to validate the tp_size parameter in the kv_transfer_params function used on OpenAI-compatible completion endpoints. Attackers can supply excessively large tp_size values in prefill/decode disaggregated deployments, leading to unbounded memory allocation requests. This can exhaust available memory resources and trigger the kernel's OOM-killer to terminate the decode worker process, resulting in denial of service.
Potential Impact
Successful exploitation allows an unauthenticated attacker to cause a denial of service by exhausting system memory, leading to the termination of the decode worker process. This disrupts normal operation of the vLLM service but does not indicate direct code execution or data compromise based on the provided information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoints to trusted users and monitor resource usage to detect abnormal memory consumption patterns.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-21T21:42:28.781Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab1acdf55bf5e2cf58d35c4
Added to database: 09/21/2026, 22:17:03 UTC
Last enriched: 09/21/2026, 22:31:32 UTC
Last updated: 09/21/2026, 22:35:16 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.