Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-93436

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 44.2%
CVSS Severity
CVSS v3 Score 7.5


Contact Us

Shodan ® - All rights reserved