---
id: CVE-2026-94570
title: >-
  SGLang contains a DoS vulnerability caused by missing input validation for
  AUX_DATA ZeroMQ control messages in the Decode worker, which enables an
  unauthenticated remote attacker with network reachability to the Decode
  control PULL socke…
summary: >-
  SGLang contains a DoS vulnerability caused by missing input validation for
  AUX_DATA ZeroMQ control messages in the Decode worker, which enables an
  unauthenticated remote attacker with network reachability to the Decode
  control PULL socke…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1287
vendor: SGLang
product: SGLang
affected:
  - SGLang <= 0.5.15
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:08:49.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94570'
references:
  - url: 'https://gist.github.com/yyymk/b5892625cb5efa2bffd36e0b05334ae8'
    label: cret@cert.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T14:55:34.311995Z'
ingestedAt: '2026-09-22T15:05:01.075Z'
epss: 0.00471
epssPercentile: 0.3995
---

## Overview

SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socket to terminate the Decode control thread and cause a denial of service against the target server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
