PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94624 vllm-project CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-21T22:17:01.280Z and has not been modified since then. The vulnerability is a denial-of-service issue in vLLM through 0.29.0, specifically in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. This allows attackers to supply arbitrary remote host and port values in kv_transfer_params, creating unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted. This causes an uncaught ZMQError that crashes EngineCore and stops all inference. Defenders should assess exposure and verify if

Vendor
vllm-project
Product
vllm
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-29
Advisory published
2026-09-21
Advisory updated
2026-09-29

Who should care

Defenders responsible for vLLM deployments, particularly those using OffloadingConnector with TieringOffloadingSpec, should assess exposure and prioritize verification and mitigation of the vulnerability.

Why it matters

Defenders should prioritize verifying exposure in vLLM deployments using OffloadingConnector with TieringOffloadingSpec, assessing the impact of potential denial-of-service attacks on inference services, and applying patches or updates to mitigate the vulnerability.

  • Potential denial-of-service attacks on inference services
  • Exhaustion of context quota due to unreachable peer sessions
  • Crash of EngineCore and interruption of inference services

Technical summary

The vLLM project contains a denial-of-service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.

Defensive priority

Defenders should prioritize verifying exposure in vLLM deployments using OffloadingConnector with TieringOffloadingSpec, assessing the impact of potential denial-of-service attacks on inference services.

Recommended defensive actions

  • Verify vLLM deployments for OffloadingConnector configurations with TieringOffloadingSpec
  • Assess the impact of potential denial-of-service attacks on inference services
  • Review and apply patches or updates to vLLM to mitigate the vulnerability
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs for exposed assets
  • Review compensating controls for exposed systems
  • Plan vendor-supported updates or mitigations through normal change control

Evidence notes

The CVE record and NVD entry provide details on the denial-of-service vulnerability in vLLM through 0.29.0. The vulnerability is related to P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94624 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94624

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94624 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94624

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.