CVE-2026-92220
Received Received - Intake

Resource Exhaustion in vLLM MoRIIO Acknowledgement Handler

Vulnerability report for CVE-2026-92220, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: VulDB

Description

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a manipulation of the argument request_id/kv_transfer_params results in resource consumption. It is possible to initiate the attack remotely. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
vllm-project vllm 0.26.0
vllm-project vllm 0.27.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a resource exhaustion issue in vLLM's MoRIIO component. It occurs when the system processes manipulated arguments like request_id or kv_transfer_params, leading to uncontrolled resource consumption. The flaw stems from unbounded growth of ACK objects due to repeated release messages for already-completed transfers, causing memory and system resource leaks.

Detection Guidance

Monitor for unusual resource consumption in vLLM processes, particularly memory and CPU usage spikes. Check logs for repeated release messages for the same request_id in the MoRIIO component. Use system monitoring tools like top, htop, or ps to observe process behavior.

Impact Analysis

This vulnerability can cause system slowdowns or crashes by consuming excessive memory and CPU resources. It may degrade performance of vLLM services, potentially leading to denial-of-service conditions where the system becomes unresponsive or fails to handle legitimate requests.

Mitigation Strategies

Apply the patch from the pull request (https://github.com/vllm-project/vllm/pull/50674) to limit ACK queue size and enforce TTL. Restart vLLM services after applying changes. Monitor system resources closely post-update to ensure stability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92220. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart