GPU VulnDB

Database/AI/ML frameworks & serving

vLLM: incomplete NIXL kv_transfer_params kills the decode engine with an uncaught KeyError

CVSS 8.7CVE-2026-94622AI/ML frameworks & servingcurated

Impact

In prefill/decode disaggregated deployments using the NIXL connector, a request carrying an incomplete kv_transfer_params dictionary reaches EngineCore scheduling and raises an uncaught KeyError, terminating the decode engine. Every request routed to that engine then fails until an operator restarts it manually - there is no self-heal. One malformed request from any caller takes down a decode tier that many tenants share, and the GPUs it owns stop serving while weights reload.

Who can reach it

Any client that can reach the vLLM OpenAI-compatible API and set kv_transfer_params. No authentication required per the record. Only disaggregated deployments with the NIXL connector are affected.

What to do

Pick up the fix in vllm-project/vllm PR #54807 (no released version is named in the record; reported through 0.29.0). Rolling out is a container image update and a restart of the decode engines - drain traffic from each replica first, since the restart reloads model weights. If you cannot patch yet, have the fronting gateway reject or overwrite client-supplied kv_transfer_params.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.