Impact
SGLang versions through 0.5.20 contain an unbounded memory allocation flaw in handle_staging_req() that does not validate the chunk_idx received from ZMQ STAGING_REQ frames. A single oversized value can force the scheduler to allocate memory until the operating system runs out, causing the process to terminate. This results in a denial of service for the affected deployment, potentially affecting all services that rely on the decode engine.
Affected Systems
The vulnerable product is SGLang by sgl-project. All releases up to and including 0.5.20 are affected. The issue arises in deployments that use the prefill/decode disaggregation mode.
Risk and Exploitability
The CVSS score of 8.2 reflects a high severity risk. The EPSS score is less than 1 %, indicating a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires access to the internal ZMQ rank port that the decode engine listens on; an attacker with that access can send a frame containing an extremely large chunk_idx value, provoking the memory exhaustion behavior.
OpenCVE Enrichment