Vulnerabilities & PatchesEmerging1 src
CVE-2026-93838 - SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
CVE ID : CVE-2026-93838
Published : Sept. 18, 2026, 8:17 p. m.
• 38 minutes ago
Description : SGLang versions through 0. 5. 20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments.
Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Severity: 8.2
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...