Impact
A flaw in vLLM's MoRIIO Acknowledgement Handler permits an attacker to manipulate request identifiers or transfer parameters to trigger excessive resource consumption, potentially degrading service availability.
Affected Systems
vLLM v0.26.0 and v0.27.0 released by the vllm-project are affected. The vulnerability resides in the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py within the MoRIIO component.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS scoring below 1% reflects a low probability that this flaw will be exploited in the wild, and the vulnerability is not yet catalogued in CISA's KEV. Nonetheless, the attack vector appears to be remote, relying on malformed request or parameter input. No official patch exists at this time, so mitigation focuses on disabling the vulnerable path and implementing input validation.
OpenCVE Enrichment