High severity7.5NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102634
CVE-2026-102634
Description
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=0.5.20
Patches
Vulnerability mechanics
References
6- github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/disaggregation/common/conn.pynvd
- github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/disaggregation/decode.pynvd
- github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/disaggregation/mooncake/conn.pynvd
- github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/managers/io_struct.pynvd
- github.com/sgl-project/sglang/issues/40125nvd
- www.vulncheck.com/advisories/sglang-through-0.5.20-denial-of-service-via-duplicate-bootstrap-roomnvd
News mentions
0No linked articles in our index yet.