PT-2026-95432 · Sglang · Sglang
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SGLang versions prior to 0.5.20
Description
When operating in prefill/decode disaggregation mode with the Mooncake KV transfer backend, the system fails to validate
bootstrap room values. This allows for unbounded transfer state allocation. Unauthenticated attackers can exploit this by sending requests to the decode engine's 'POST /generate' endpoint with arbitrary bootstrap room values, leading to memory exhaustion in the prefill process and subsequent out-of-memory termination.Recommendations
Update SGLang to version 0.5.20 or later.
Avoid using arbitrary values in the
bootstrap room parameter when calling the 'POST /generate' endpoint until the update is applied.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sglang