CVE-2026-94624: Vllm

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.

Affected products

  • Vllm Vllm: up to and including 0.29.0

Published 2026-09-21. Last modified 2026-09-29.