Description
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (memory exhaustion)
Action: Immediate Patch
AI Analysis

Impact

SGLang up to version 0.5.19 contains an unchecked bootstrap_room parameter in the prefill/decode disaggregation mode when the Mooncake KV transfer backend is used. Because the application does not validate this value, an attacker that can invoke the prefill process through the POST /generate endpoint can transmit arbitrarily large bootstrap_room data. This causes the server to allocate proportionally large amounts of transfer state memory, eventually exhausting available memory and triggering an out‑of‑memory termination of the prefill process, thereby disrupting service availability.

Affected Systems

The SGLang package from sgl-project. All releases through 0.5.19 are vulnerable, specifically when operating in prefill/decode disaggregation mode with the Mooncake KV transfer backend enabled.

Risk and Exploitability

The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score of 0.00396 (≈0.4%) indicates a low but measurable probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. The attack vector is remote and unauthenticated—any entity able to send HTTP POST requests to the /generate endpoint can trigger the flaw. While the impact is limited to service availability, the high severity and lack of built‑in protection make it a significant risk to affected deployments.

Generated by OpenCVE AI on September 19, 2026 at 18:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SGLang version 0.5.20 or newer to receive the missing bootstrap_room validation fix.
  • Restrict unauthenticated access to the POST /generate endpoint by configuring a reverse proxy, firewall, or authentication layer so only trusted traffic can reach it.
  • Apply container or host–level memory limits (e.g., cgroups, Docker memory limits) to the prefill process to prevent excessive allocation from exhausting system resources.

Generated by OpenCVE AI on September 19, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Sgl-project
Sgl-project sglang
Vendors & Products Sgl-project
Sgl-project sglang

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.
Title SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room
First Time appeared Lmsys
Lmsys sglang
Weaknesses CWE-770
CPEs cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:*
Vendors & Products Lmsys
Lmsys sglang
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:51:15.971Z

Reserved: 2026-09-18T14:39:01.470Z

Link: CVE-2026-93688

cve-icon Vulnrichment

Updated: 2026-09-21T16:28:52.903Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:15.683

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-93688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling