CVE-2026-102634: SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstraproom fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstraproom values to crash scheduler processes or hang other users' requests until transfer timeout.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
SGLang deployments through 0.5.20 are affected when they use prefill/decode disaggregation mode with the Mooncake KV transfer backend. The issue is triggered through the /generate endpoint.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They can send concurrent /generate requests that use the same bootstrap_room value.
What is the operational impact of exploitation?
Exploitation can crash scheduler processes or cause other users' requests to hang until the KV transfer timeout expires. The reported impact is availability only; no confidentiality or integrity impact is indicated.