CVE-2026-92972: SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint

Published Sep 17, 2026
·
Updated

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rankip and rankport values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including session identifiers and tensor-parallel topology parameters.

Affected Software

1 affected component
SGLang<=0.5.19

Event History

Sep 17, 2026
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

SGLang deployments through 0.5.19 that use prefill/decode disaggregation mode are affected if the prefill bootstrap service's PUT /route endpoint is reachable by an attacker. The issue concerns the routing table used for KV transfer between prefill and decode workers.

2

What does an attacker need to exploit it?

An attacker does not need authentication, user interaction, or prior privileges. They need network access to the prefill bootstrap service and the ability to send a PUT request to /route with chosen rank_ip and rank_port values.

3

What can happen if exploitation succeeds?

An attacker can redirect decode workers to attacker-controlled endpoints by poisoning KV transfer routing entries. This can cause denial of service and may disclose KV transfer metadata, including session identifiers and tensor-parallel topology parameters.

4

What can be done while patching is unavailable?

Restrict network access to the prefill bootstrap service so untrusted systems cannot reach its PUT /route endpoint. In particular, limit access to the network paths used only by authorized prefill and decode components.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203