Improper Handling of Exceptional Conditions Affecting vllm package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.52% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-VLLM-20044434
  • published22 Sept 2026
  • disclosed21 Sept 2026
  • creditUnknown

Introduced: 21 Sep 2026

NewCVE-2026-94625  (opens in a new tab)
CWE-755  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs

Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions in mooncake_connector.py via the Mooncake KV transfer connector, when a remote KV cache load fails during receive_kv_from_single_worker, the failure is not reported back to the scheduler. Instead of propagating the error so the scheduler can fail or recompute the affected request, the connector silently discards the failure, leaving the scheduler unaware that the transfer did not complete. This causes the affected request to stall indefinitely, resulting in a denial of service for that inference request. An unauthenticated remote attacker can trigger this condition by causing a KV transfer error over the network.

CVSS Base Scores

version 4.0
version 3.1