Description
SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rank_ip and rank_port values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including session identifiers and tensor-parallel topology parameters.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and Information Disclosure through unauthenticated route poisoning
Action: Immediate Patch
AI Analysis

Impact

SGLang versions up to 0.5.19 expose an unauthenticated HTTP PUT endpoint at /route on the prefill bootstrap service used for disaggregation. An attacker can supply arbitrary rank_ip and rank_port values, causing the system to modify its key‑value routing table and redirect decode workers to attacker‑controlled endpoints. This manipulation can lead to denial of service, as legitimate workers are misdirected, and can also leak sensitive KV transfer metadata such as session identifiers and tensor‑parallel topology parameters.

Affected Systems

The vulnerability affects the sgl-project sglang software up to and including version 0.5.19 when operating in prefill/decode disaggregation mode. Systems using the prefill bootstrap service that expose the PUT /route endpoint are at risk.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity, and the lack of authentication makes exploitation straightforward for any entity capable of reaching the service. Although no EPSS score is available, the vulnerability is not listed in CISA’s KEV, indicating that no widespread exploitation has been reported yet, but the potential impact warrants concern.

Generated by OpenCVE AI on September 18, 2026 at 00:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade sgllang to a version newer than 0.5.19 where the PUT /route endpoint is removed or secured.
  • Restrict network access to the prefill bootstrap service so that only trusted internal hosts can call the /route endpoint.
  • Configure firewalls or network segmentation to block unauthenticated HTTP PUT requests to /route from all external networks.

Generated by OpenCVE AI on September 18, 2026 at 00:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Sgl-project
Sgl-project sglang
Vendors & Products Sgl-project
Sgl-project sglang

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rank_ip and rank_port values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including session identifiers and tensor-parallel topology parameters.
Title SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Sgl-project Sglang
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T16:23:32.042Z

Reserved: 2026-09-17T13:23:59.248Z

Link: CVE-2026-92972

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:52.005Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:03.347

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:15:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function