PT-2026-95637 · Sglang · Sglang
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SGLang versions prior to 0.5.20
Description
An unbounded memory allocation issue exists in the
handle staging req() function within prefill/decode disaggregation deployments. The system fails to validate the chunk idx variable received from ZMQ STAGING REQ frames. An attacker with access to the internal ZMQ rank port of the decode engine can send a frame containing an excessively large chunk idx value, leading the scheduler to allocate memory until system resources are exhausted and the process terminates.Recommendations
Update to version 0.5.20 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sglang