Improper Handling of Exceptional Conditions Affecting vllm package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.63% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-VLLM-20044441
  • published22 Sept 2026
  • disclosed21 Sept 2026
  • creditUnknown

Introduced: 21 Sep 2026

NewCVE-2026-94627  (opens in a new tab)
CWE-755  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

vllm is an A high-throughput and memory-efficient inference and serving engine for LLMs

Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions in mooncake_connector.py, the Mooncake KV connector's receiver loop fails to report remote KV load failures back to the scheduler. When a remote KV cache transfer returns an error or raises an exception, the failure is only logged and the affected request's block IDs are never marked invalid, leaving the scheduler unaware that the transfer did not complete. This causes the scheduler to stall waiting for results that will never arrive, resulting in a crash or hang that denies service to all pending requests.

CVSS Base Scores

version 4.0
version 3.1