Impact
SGLang versions up to 0.5.19 expose an unauthenticated HTTP PUT endpoint at /route on the prefill bootstrap service used for disaggregation. An attacker can supply arbitrary rank_ip and rank_port values, causing the system to modify its key‑value routing table and redirect decode workers to attacker‑controlled endpoints. This manipulation can lead to denial of service, as legitimate workers are misdirected, and can also leak sensitive KV transfer metadata such as session identifiers and tensor‑parallel topology parameters.
Affected Systems
The vulnerability affects the sgl-project sglang software up to and including version 0.5.19 when operating in prefill/decode disaggregation mode. Systems using the prefill bootstrap service that expose the PUT /route endpoint are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, and the lack of authentication makes exploitation straightforward for any entity capable of reaching the service. Although no EPSS score is available, the vulnerability is not listed in CISA’s KEV, indicating that no widespread exploitation has been reported yet, but the potential impact warrants concern.
OpenCVE Enrichment