CVE-2026-102634 Details
Description
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
A denial-of-service vulnerability has been identified in SGLang versions through 0.5.20. The issue arises in prefill and decode disaggregation modes when the Mooncake KV transfer backend is used. The vulnerability allows unauthenticated attackers to send concurrent requests with identical bootstrap_room values, leading to a crash in the scheduler processes or causing other users' requests to hang until a transfer timeout occurs.
Users should update to SGLang version 0.5.21 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-694 | Use of Multiple Resources with Duplicate Identifier | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SGLang | <= 0.5.20 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion