Description
SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Published: 2026-09-18
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Title SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
First Time appeared Lmsys
Lmsys sglang
Weaknesses CWE-770
CPEs cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:*
Vendors & Products Lmsys
Lmsys sglang
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T20:09:44.508Z

Reserved: 2026-09-18T18:16:36.587Z

Link: CVE-2026-93838

cve-icon Vulnrichment

Updated: 2026-09-18T20:09:03.860Z

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:33.900

Modified: 2026-09-18T21:18:48.890

Link: CVE-2026-93838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses