CVE-2026-10775: sgl-project SGLang Cache data_hash denial of service
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function datahash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10775?
The severity of CVE-2026-10775 is rated as low with a score of 3.6.
How does CVE-2026-10775 affect the SGLang software?
CVE-2026-10775 affects the data_hash function of the Cache Handler in SGLang, leading to a denial of service.
What type of attack does CVE-2026-10775 enable?
CVE-2026-10775 enables a denial of service attack that requires local execution and has a high complexity level.
What versions of SGLang are impacted by CVE-2026-10775?
SGLang versions up to 0.5.11 are impacted by CVE-2026-10775.
How can I mitigate the risks associated with CVE-2026-10775?
To mitigate the risks associated with CVE-2026-10775, it is recommended to upgrade to a patched version of SGLang.