Database/AI/ML frameworks & serving
vLLM: Mooncake transfer-ID collision leaks GPU KV cache blocks until restart
Impact
When concurrent child requests of one multi-prompt completion share a single Mooncake transfer ID, KV cache block ownership is mishandled and blocks are orphaned instead of freed. The leak is in GPU memory, so it accumulates request after request until the cache cannot serve legitimate work; only a process restart reclaims it. On shared inference capacity this is a slow, self-inflicted-looking degradation - latency and admission failures rise long before anything crashes - which makes it easy to misdiagnose as capacity pressure rather than an attack or a bug.
Who can reach it
Any client that can submit multi-prompt completion requests to a disaggregated vLLM deployment using the Mooncake connector. No authentication required per the record.
What to do
Apply vllm-project/vllm PR #49796; no fixed release is named (reported through 0.29.0). Deployment is an image update plus a restart of the affected serving processes, which is also the only way to reclaim already-leaked blocks. Monitor GPU KV cache utilisation as a leak indicator in the meantime.
References
Related entries
- Gradio (`/queue/join`): SSRFCVE-2024-4325 · Gradio (`/queue/join`)High
- ONNX: Security-control bypass through 1.20.1CVE-2026-28500 · ONNXHigh
- ONNX (`ExternalDataInfo`): Security control bypass in external-data path handlingCVE-2026-34445 · ONNX (`ExternalDataInfo`)High
- JupyterLab: saved HTML cell output can run arbitrary JupyterLab commands on one user clickCVE-2026-42557 · JupyterLab (HTML sanitizer / CommandLinker command dispatch)High
- LocalAI (`/models/apply`): Unauthenticated SSRF fetching arbitrary internal URLsCVE-2026-59707 · LocalAI (`/models/apply`)High
- Text Generation Inference (TGI): SSRF in the OpenAI-compatible multimodal chat endpointCVE-2026-63086 · Text Generation Inference (TGI)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.