SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout. | |
| Title | SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room | |
| First Time appeared |
Lmsys
Lmsys sglang |
|
| Weaknesses | CWE-694 | |
| CPEs | cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lmsys
Lmsys sglang |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T17:33:09.537Z
Reserved: 2026-09-29T15:50:38.222Z
Link: CVE-2026-102634
No data.
Status : Deferred
Published: 2026-09-29T17:17:07.147
Modified: 2026-09-29T17:17:07.280
Link: CVE-2026-102634
No data.
OpenCVE Enrichment
No data.
Weaknesses