VulnSea

sgl-project has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
3 prev 0

Weakness classes

Products

  • sglang 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

sgl-project vulnerabilities

CVEs affecting sgl-project, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-93838Medium· 5.9PoC
4d ago

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …

Twilightsgl-project · sglangEPSS 0.46%via NVD
CVE-2026-93688High· 7.5
4d ago

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's …

Twilightsgl-project · sglangEPSS 0.40%via NVD
CVE-2026-92972High· 8.6
5d ago

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary ra…

Twilightsgl-project · sglangEPSS 0.33%via NVD
sgl-project vulnerabilities (CVEs) · VulnSea