Description
SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Published: 2026-09-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

SGLang versions through 0.5.20 contain an unbounded memory allocation flaw in handle_staging_req() that does not validate the chunk_idx received from ZMQ STAGING_REQ frames. A single oversized value can force the scheduler to allocate memory until the operating system runs out, causing the process to terminate. This results in a denial of service for the affected deployment, potentially affecting all services that rely on the decode engine.

Affected Systems

The vulnerable product is SGLang by sgl-project. All releases up to and including 0.5.20 are affected. The issue arises in deployments that use the prefill/decode disaggregation mode.

Risk and Exploitability

The CVSS score of 8.2 reflects a high severity risk. The EPSS score is less than 1 %, indicating a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires access to the internal ZMQ rank port that the decode engine listens on; an attacker with that access can send a frame containing an extremely large chunk_idx value, provoking the memory exhaustion behavior.

Generated by OpenCVE AI on September 19, 2026 at 17:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SGLang to a version later than 0.5.20 which contains the fix for the unbounded memory allocation flaw.
  • Ensure the internal ZMQ rank port used by the decode engine is not exposed to untrusted networks; limit connectivity to trusted hosts only.
  • Configure network or firewall rules to restrict or filter access to the ZMQ rank port, and monitor for anomalous frames with unusually large chunk_idx values.

Generated by OpenCVE AI on September 19, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Sgl-project
Sgl-project sglang
Vendors & Products Sgl-project
Sgl-project sglang

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Title SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
First Time appeared Lmsys
Lmsys sglang
Weaknesses CWE-770
CPEs cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:*
Vendors & Products Lmsys
Lmsys sglang
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:13.073Z

Reserved: 2026-09-18T18:16:36.587Z

Link: CVE-2026-93838

cve-icon Vulnrichment

Updated: 2026-09-18T20:09:03.860Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:33.900

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-93838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:10Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling