CyberRota Analysis
AI-GeneratedThe vulnerability in SGLang allows unauthenticated attackers to exploit the system by sending concurrent requests with duplicate bootstrap_room values, potentially crashing scheduler processes or causing significant delays for other users. This poses a high risk to systems utilizing the Mooncake KV transfer backend, as it can disrupt service availability and degrade user experience. Organizations using affected versions should prioritize patching to mitigate the risk of denial-of-service attacks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.