Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process. | |
| Title | SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx | |
| First Time appeared |
Lmsys
Lmsys sglang |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lmsys
Lmsys sglang |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T20:09:44.508Z
Reserved: 2026-09-18T18:16:36.587Z
Link: CVE-2026-93838
Updated: 2026-09-18T20:09:03.860Z
Status : Received
Published: 2026-09-18T20:17:33.900
Modified: 2026-09-18T21:18:48.890
Link: CVE-2026-93838
No data.
OpenCVE Enrichment
No data.
