CVE-2026-94626: Vllm
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.
Affected products
- Vllm Vllm: up to and including 0.29.0
Published 2026-09-21. Last modified 2026-09-29.