CVE-2026-102634: Use of Multiple Resources with Duplicate Identifier in sgl-project sglang
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
AI Analysis
Technical Summary
The vulnerability in sglang through version 0.5.20 arises from improper validation of duplicate bootstrap_room fields in /generate requests under the Mooncake KV transfer backend during prefill/decode disaggregation mode. An attacker without authentication can exploit this by sending multiple concurrent requests with the same bootstrap_room identifier, leading to scheduler process crashes or request hangs until the transfer timeout is reached. This denial-of-service condition affects the availability of the service.
Potential Impact
Exploitation of this vulnerability results in denial-of-service conditions by crashing scheduler processes or causing request hangs for other users until the transfer timeout. The attack requires no authentication and can disrupt normal service operation, impacting availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider implementing request rate limiting or input validation controls to detect and block duplicate bootstrap_room values in /generate requests if feasible.
CVE-2026-102634: Use of Multiple Resources with Duplicate Identifier in sgl-project sglang
Description
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
CVSS v4.0
Score 8.7high
Affected software
sgl-project
sglang
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in sglang through version 0.5.20 arises from improper validation of duplicate bootstrap_room fields in /generate requests under the Mooncake KV transfer backend during prefill/decode disaggregation mode. An attacker without authentication can exploit this by sending multiple concurrent requests with the same bootstrap_room identifier, leading to scheduler process crashes or request hangs until the transfer timeout is reached. This denial-of-service condition affects the availability of the service.
Potential Impact
Exploitation of this vulnerability results in denial-of-service conditions by crashing scheduler processes or causing request hangs for other users until the transfer timeout. The attack requires no authentication and can disrupt normal service operation, impacting availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider implementing request rate limiting or input validation controls to detect and block duplicate bootstrap_room values in /generate requests if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-29T15:50:38.222Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abbf0c0c9b3d5d17704c501
Added to database: 09/29/2026, 17:09:20 UTC
Last enriched: 09/29/2026, 17:13:59 UTC
Last updated: 09/29/2026, 18:20:12 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.