PT-2026-96762 · Sglang · Sglang
CVE-2026-94570
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SGLang versions prior to 0.5.20
Description
SGLang is subject to a denial of service issue due to missing input validation for AUX DATA ZeroMQ control messages within the Decode worker. An unauthenticated remote attacker with network access to the Decode control PULL socket can terminate the Decode control thread, resulting in a denial of service for the target server.
Recommendations
Update to version 0.5.20.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sglang