{"id":"CVE-2026-92972","summary":"SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint","details":"SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rank_ip and rank_port values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including session identifiers and tensor-parallel topology parameters.","modified":"2026-09-24T03:30:33.081788919Z","published":"2026-09-17T13:43:16.670Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-306"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92972.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92972.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92972"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sglang-through-0.5.19-unauthenticated-route-poisoning-via-put-endpoint"},{"type":"REPORT","url":"https://github.com/sgl-project/sglang/issues/39400"},{"type":"PACKAGE","url":"https://github.com/sgl-project/sglang"},{"type":"ARTICLE","url":"https://github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/disaggregation/common/conn.py#L1716-L1718"},{"type":"ARTICLE","url":"https://github.com/sgl-project/sglang/blob/v0.5.19/python/sglang/srt/disaggregation/common/conn.py#L1736-L1810"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sgl-project/sglang","events":[{"introduced":"0"},{"fixed":"0bcd822377da7b5718e674eaf9c870d349424dd1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.5.19"},{"fixed":"0.5.19"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["gateway-v0.3.1","gateway-v0.3.0","v0.5.6.post2","gateway-v0.2.4","v0.5.6.post1","v0.5.6","v0.5.5","v0.5.5.post3","gateway-v0.2.3","v0.5.5.post2","v0.5.5.post1","v0.5.4.post3","v0.5.4.post2","gateway-v0.2.2","v0.5.4.post1","v0.5.4","gateway-v0.2.1","v0.5.3.post3","v0.5.3.post2","gateway-v0.2.0","v0.5.3.post1","v0.5.3","v0.5.3rc2","v0.5.3rc1","v0.5.3rc0","v0.5.2","v0.5.2rc2","v0.5.2rc1","v0.5.2rc0","v0.5.1.post3","v0.5.1.post2","v0.5.1.post1","v0.5.1","v0.5.0rc2","v0.5.0rc1","v0.5.0rc0","gateway-v0.1.9","v0.4.10.post2","v0.4.10.post1","gateway-v0.1.8","gateway-v0.1.7","v0.4.10","v0.4.9.post6","v0.4.9.post5","v0.4.9.post4","v0.4.9.post3","gateway-v0.1.6","v0.4.9.post2","v0.4.9.post1","gateway-v0.1.5","v0.4.9","v0.4.8.post1","v0.4.8","v0.4.7.post1","v0.4.7","v0.4.6.post5","v0.4.6.post4","v0.4.6.post3","v0.4.6.post2","v0.4.6.post1","v0.4.6","v0.4.5.post3","v0.4.5.post2","v0.4.5.post1","v0.4.5","v0.4.4.post4","v0.4.4.post3","v0.4.4.post2","v0.4.4.post1","v0.4.4","v0.4.3.post4","v0.4.3.post3","v0.4.3.post2","v0.4.3.post1","v0.4.3","v0.4.2.post4","v0.4.2.post3","v0.4.2.post2","v0.4.2.post1","v0.4.2","v0.4.1.post7","v0.4.1.post6","v0.4.1.post5","v0.4.1.post4","v0.4.1.post3","v0.4.1.post2","v0.4.1.post1","v0.4.1","v0.4.0.post2","v0.4.0.post1","v0.4.0","v0.3.6.post3","v0.3.6.post2","v0.3.6.post1","v0.3.6","v0.3.5.post2","v0.3.5.post1","v0.3.5","v0.3.4.post2","v0.3.4.post1","v0.3.4","v0.3.3.post1","v0.3.3","v0.3.2","v0.3.1.post3","v0.3.1.post2","v0.3.1.post1","v0.3.0","v0.2.15","v0.2.14.post2","v0.2.14.post1","v0.2.14","v0.2.13","v0.2.12","v0.2.11","v0.2.10","v0.2.9.post1","v0.2.9","v0.2.8","v0.2.7","v0.2.6","v0.2.5","v0.2.0","v0.1.24","v0.1.23","v0.1.22","v0.1.21","v0.1.20","v0.1.19","v0.1.18","v0.1.17","v0.1.16","v0.1.15","v0.1.14","v0.1.13","v0.1.12","v0.1.11","v0.1.10","v0.1.9","v0.1.8","v0.1.7","v0.1.6","v0.1.5","v0.1.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92972.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"}]}