← Back to CVE List
CVE-2026-92972NVD
Vulnerability Summary
SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rank_ip and rank_port values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including session identifiers and tensor-parallel topology parameters.
CVSS v4.0 Base Metrics — Score 8.8 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 8.6 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityHigh
Affected & Patched Versions
- sgl-project sglang <= 0.5.19
- sgl-project sglang 0.5.19
External References
- https://github.com/sgl-project/sglang/issues/39400
- https://github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/disaggregation/common/conn.py#L1736-L1810
- https://github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/disaggregation/common/conn.py#L1716-L1718
- https://github.com/sgl-project/sglang
- https://www.vulncheck.com/advisories/sglang-through-0.5.19-unauthenticated-route-poisoning-via-put-endpoint