Impact
SGLang up to version 0.5.19 contains an unchecked bootstrap_room parameter in the prefill/decode disaggregation mode when the Mooncake KV transfer backend is used. Because the application does not validate this value, an attacker that can invoke the prefill process through the POST /generate endpoint can transmit arbitrarily large bootstrap_room data. This causes the server to allocate proportionally large amounts of transfer state memory, eventually exhausting available memory and triggering an out‑of‑memory termination of the prefill process, thereby disrupting service availability.
Affected Systems
The SGLang package from sgl-project. All releases through 0.5.19 are vulnerable, specifically when operating in prefill/decode disaggregation mode with the Mooncake KV transfer backend enabled.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score of 0.00396 (≈0.4%) indicates a low but measurable probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. The attack vector is remote and unauthenticated—any entity able to send HTTP POST requests to the /generate endpoint can trigger the flaw. While the impact is limited to service availability, the high severity and lack of built‑in protection make it a significant risk to affected deployments.
OpenCVE Enrichment