High severity7.5NVD Advisory· Published Sep 21, 2026
CVE-2026-94623
CVE-2026-94623
Description
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.