High severity7.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93688
CVE-2026-93688
Description
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.
Affected products
1- Range: <=0.5.19
Patches
Vulnerability mechanics
References
6- github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/disaggregation/mooncake/conn.pynvd
- github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/disaggregation/mooncake/conn.pynvd
- github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/managers/io_struct.pynvd
- github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/managers/scheduler.pynvd
- github.com/sgl-project/sglang/issues/39428nvd
- www.vulncheck.com/advisories/sglang-through-0.5.19-unbounded-memory-allocation-via-bootstrap-roomnvd
News mentions
0No linked articles in our index yet.