← All credits
Mingkai Yu
26 vulnerability records and advisories credit this contributor.
CVE-2026-103041
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service
CVE-2026-102634
SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room
CVE-2026-94622
vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata
CVE-2026-94623
vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure
CVE-2026-94624
vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions
CVE-2026-94625
vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders
CVE-2026-94626
vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size
CVE-2026-94627
vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision
CVE-2026-93840
vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids
CVE-2026-93841
vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs