PatchSiren cyber security CVE debrief
CVE-2026-94624 vllm-project CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-21T22:17:01.280Z and has not been modified since then. The vulnerability is a denial-of-service issue in vLLM through 0.29.0, specifically in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. This allows attackers to supply arbitrary remote host and port values in kv_transfer_params, creating unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted. This causes an uncaught ZMQError that crashes EngineCore and stops all inference. Defenders should assess exposure and verify if
- Vendor
- vllm-project
- Product
- vllm
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for vLLM deployments, particularly those using OffloadingConnector with TieringOffloadingSpec, should assess exposure and prioritize verification and mitigation of the vulnerability.
Why it matters
Defenders should prioritize verifying exposure in vLLM deployments using OffloadingConnector with TieringOffloadingSpec, assessing the impact of potential denial-of-service attacks on inference services, and applying patches or updates to mitigate the vulnerability.
- Potential denial-of-service attacks on inference services
- Exhaustion of context quota due to unreachable peer sessions
- Crash of EngineCore and interruption of inference services
Technical summary
The vLLM project contains a denial-of-service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.
Defensive priority
Defenders should prioritize verifying exposure in vLLM deployments using OffloadingConnector with TieringOffloadingSpec, assessing the impact of potential denial-of-service attacks on inference services.
Recommended defensive actions
- Verify vLLM deployments for OffloadingConnector configurations with TieringOffloadingSpec
- Assess the impact of potential denial-of-service attacks on inference services
- Review and apply patches or updates to vLLM to mitigate the vulnerability
- Track exceptions and retest remediated assets
- Check relevant monitoring, detection, and logs for exposed assets
- Review compensating controls for exposed systems
- Plan vendor-supported updates or mitigations through normal change control
Evidence notes
The CVE record and NVD entry provide details on the denial-of-service vulnerability in vLLM through 0.29.0. The vulnerability is related to P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94624 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94624
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94624 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94624
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/v1/kv_offload/tiering/p2p/control/zmq.py
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/v1/kv_offload/tiering/p2p/manager.py
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/vllm-project/vllm/pull/51504
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/vllm-through-0.29.0-denial-of-service-via-unbounded-p2p-kv-offloading-sessions
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.