The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsA fix was pushed into the master branch but not yet published.
vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs
Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions in mooncake_connector.py via the Mooncake KV transfer connector, when a remote KV cache load fails during receive_kv_from_single_worker, the failure is not reported back to the scheduler. Instead of propagating the error so the scheduler can fail or recompute the affected request, the connector silently discards the failure, leaving the scheduler unaware that the transfer did not complete. This causes the affected request to stall indefinitely, resulting in a denial of service for that inference request. An unauthenticated remote attacker can trigger this condition by causing a KV transfer error over the network.