PT-2026-95637 · Sglang · Sglang

·

CVE-2026-93838

·

Published

2026-09-18

·

Updated

2026-09-27

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SGLang versions prior to 0.5.20
Description An unbounded memory allocation issue exists in the handle staging req() function within prefill/decode disaggregation deployments. The system fails to validate the chunk idx variable received from ZMQ STAGING REQ frames. An attacker with access to the internal ZMQ rank port of the decode engine can send a frame containing an excessively large chunk idx value, leading the scheduler to allocate memory until system resources are exhausted and the process terminates.
Recommendations Update to version 0.5.20 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93838
OPENSUSE-SU-2026:11865-1

Affected Products

Sglang