CVE-2026-92220 Details
Description
A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a manipulation of the argument request_id/kv_transfer_params results in resource consumption. It is possible to initiate the attack remotely. The project was informed of the problem early through a pull request but has not reacted yet.
A resource exhaustion vulnerability has been identified in vLLM versions 0.26.0 and 0.27.0. The issue arises in the MoRIIO Acknowledgement Handler component, specifically within the function handling release messages. Manipulating the request_id or kv_transfer_params arguments can lead to excessive resource consumption. This vulnerability can be exploited remotely.
Users can update to vLLM version 0.29.0, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vllm-project/vllm/ | [email protected] | Vendor |
| https://github.com/vllm-project/vllm/pull/50674 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-92220 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/934149 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/404470 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/404470/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vllm-project vLLM | 0.26.0 (semver) 0.27.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion