CVE-2026-102634
Deferred Deferred - Pending Action

SGLang Disaggregation Mode Bootstrap Room Validation Flaw

Vulnerability report for CVE-2026-102634, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sgl_project sglang 0.5.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-694 The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102634 is a Denial of Service (DoS) vulnerability in SGLang through version 0.5.20. When operating in prefill/decode disaggregation mode with the Mooncake KV transfer backend, the system fails to validate duplicate bootstrap_room fields in /generate requests. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values, causing scheduler processes to crash or hang other users' requests until transfer timeout.

Detection Guidance

Monitor for repeated identical bootstrap_room values in /generate requests to SGLang endpoints. Check scheduler logs for crashes or hangs during concurrent requests. Inspect network traffic for duplicate room identifiers targeting disaggregation mode.

Impact Analysis

This vulnerability allows attackers to disrupt service availability by crashing scheduler processes or delaying legitimate user requests. Systems using SGLang in disaggregation mode with Mooncake KV backend may experience crashes, hangs, or resource exhaustion, leading to service unavailability for all users.

Mitigation Strategies

Upgrade SGLang to a patched version beyond 0.5.20. Implement input validation to reject duplicate bootstrap_room values in /generate requests. Restrict access to /generate endpoints to trusted clients only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102634. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart