sgl-project sglang
5 known vulnerabilities in sgl-project sglang, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105245 CVSS 2.9 low A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file…
- CVE-2026-102634 CVSS 8.7 high SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with…
- CVE-2026-93838 CVSS 8.2 high SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate…
- CVE-2026-93688 CVSS 8.7 high SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values…
- CVE-2026-92972 CVSS 8.8 high SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap…