PT-2026-94337 · Git+1 · Sglang
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SGLang versions prior to 0.5.20
Description
When operating in prefill/decode disaggregation mode, the prefill bootstrap service exposes an unauthenticated PUT '/route' endpoint. This allows an attacker to poison the KV transfer routing table by providing arbitrary
rank ip and rank port values. Consequently, decode workers can be redirected to endpoints controlled by the attacker, leading to a denial of service or the disclosure of KV transfer metadata, such as session identifiers and tensor-parallel topology parameters.Recommendations
Update SGLang to version 0.5.20 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sglang