VYPR

Mooncake connector

by Vllm

Source repositories

CVEs (1)

  • CVE-2026-94627HigSep 21, 2026
    risk 0.42cvss 7.5epss 0.01

    vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with…