No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a manipulation of the argument request_id/kv_transfer_params results in resource consumption. It is possible to initiate the attack remotely. The project was informed of the problem early through a pull request but has not reacted yet. | |
| Title | vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._handle_release_message resource consumption | |
| First Time appeared |
Vllm-project
Vllm-project vllm |
|
| Weaknesses | CWE-400 CWE-404 |
|
| CPEs | cpe:2.3:a:vllm-project:vllm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vllm-project
Vllm-project vllm |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-16T02:15:10.740Z
Reserved: 2026-09-15T18:42:00.653Z
Link: CVE-2026-92220
No data.
Status : Received
Published: 2026-09-16T03:17:00.407
Modified: 2026-09-16T03:17:00.407
Link: CVE-2026-92220
No data.
OpenCVE Enrichment
No data.