{"id":"CVE-2026-93838","summary":"SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx","details":"SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.","modified":"2026-09-25T03:30:29.799159864Z","published":"2026-09-18T19:06:03.899Z","related":["openSUSE-SU-2026:11865-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93838.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93838.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93838"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sglang-through-0.5.20-unbounded-memory-allocation-via-staging-req-chunk-idx"},{"type":"REPORT","url":"https://github.com/sgl-project/sglang/issues/39764"},{"type":"PACKAGE","url":"https://github.com/sgl-project/sglang"},{"type":"PACKAGE","url":"https://pypi.org/project/sglang"},{"type":"ARTICLE","url":"https://github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/disaggregation/common/conn.py#L1636-L1640"},{"type":"ARTICLE","url":"https://github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/disaggregation/common/staging_handler.py#L781"},{"type":"ARTICLE","url":"https://github.com/sgl-project/sglang/blob/v0.5.20/python/sglang/srt/disaggregation/common/staging_handler.py#L848-L860"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sgl-project/sglang","events":[{"introduced":"0"},{"fixed":"94602c9c2b7cbdb8efd5c52802dac6a1c180089e"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.5.20"},{"fixed":"0.5.20"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["gateway-v0.3.1","gateway-v0.3.0","v0.5.6.post2","gateway-v0.2.4","v0.5.6.post1","v0.5.6","v0.5.5","v0.5.5.post3","gateway-v0.2.3","v0.5.5.post2","v0.5.5.post1","v0.5.4.post3","v0.5.4.post2","gateway-v0.2.2","v0.5.4.post1","v0.5.4","gateway-v0.2.1","v0.5.3.post3","v0.5.3.post2","gateway-v0.2.0","v0.5.3.post1","v0.5.3","v0.5.3rc2","v0.5.3rc1","v0.5.3rc0","v0.5.2","v0.5.2rc2","v0.5.2rc1","v0.5.2rc0","v0.5.1.post3","v0.5.1.post2","v0.5.1.post1","v0.5.1","v0.5.0rc2","v0.5.0rc1","v0.5.0rc0","gateway-v0.1.9","v0.4.10.post2","v0.4.10.post1","gateway-v0.1.8","gateway-v0.1.7","v0.4.10","v0.4.9.post6","v0.4.9.post5","v0.4.9.post4","v0.4.9.post3","gateway-v0.1.6","v0.4.9.post2","v0.4.9.post1","gateway-v0.1.5","v0.4.9","v0.4.8.post1","v0.4.8","v0.4.7.post1","v0.4.7","v0.4.6.post5","v0.4.6.post4","v0.4.6.post3","v0.4.6.post2","v0.4.6.post1","v0.4.6","v0.4.5.post3","v0.4.5.post2","v0.4.5.post1","v0.4.5","v0.4.4.post4","v0.4.4.post3","v0.4.4.post2","v0.4.4.post1","v0.4.4","v0.4.3.post4","v0.4.3.post3","v0.4.3.post2","v0.4.3.post1","v0.4.3","v0.4.2.post4","v0.4.2.post3","v0.4.2.post2","v0.4.2.post1","v0.4.2","v0.4.1.post7","v0.4.1.post6","v0.4.1.post5","v0.4.1.post4","v0.4.1.post3","v0.4.1.post2","v0.4.1.post1","v0.4.1","v0.4.0.post2","v0.4.0.post1","v0.4.0","v0.3.6.post3","v0.3.6.post2","v0.3.6.post1","v0.3.6","v0.3.5.post2","v0.3.5.post1","v0.3.5","v0.3.4.post2","v0.3.4.post1","v0.3.4","v0.3.3.post1","v0.3.3","v0.3.2","v0.3.1.post3","v0.3.1.post2","v0.3.1.post1","v0.3.0","v0.2.15","v0.2.14.post2","v0.2.14.post1","v0.2.14","v0.2.13","v0.2.12","v0.2.11","v0.2.10","v0.2.9.post1","v0.2.9","v0.2.8","v0.2.7","v0.2.6","v0.2.5","v0.2.0","v0.1.24","v0.1.23","v0.1.22","v0.1.21","v0.1.20","v0.1.19","v0.1.18","v0.1.17","v0.1.16","v0.1.15","v0.1.14","v0.1.13","v0.1.12","v0.1.11","v0.1.10","v0.1.9","v0.1.8","v0.1.7","v0.1.6","v0.1.5","v0.1.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93838.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}