Database/AI/ML frameworks & serving

SGLang: duplicate bootstrap_room values crash or hang the disaggregated scheduler
Impact
In prefill/decode disaggregated mode with the Mooncake KV transfer backend, /generate does not check that bootstrap_room is unique. Concurrent requests carrying the same bootstrap_room crash the scheduler process or leave other users' requests hanging until the transfer timeout expires. On a shared inference tier this is a cross-tenant availability problem: one caller's requests stall or kill a scheduler that many tenants route through, and the GPUs behind it sit idle while the process is restarted. Any unauthenticated client that can reach the endpoint can repeat it.
Who can reach it
Anyone who can send HTTP requests to the SGLang /generate endpoint. No authentication required, per the record. Only deployments running prefill/decode disaggregation with the Mooncake backend are affected.
What to do
No fixed version is named in the record - the flaw is reported through 0.5.20. Track the sgl-project/sglang repository for the fix. Meanwhile keep the serving endpoint behind a gateway that authenticates callers and strips or regenerates bootstrap_room, and be ready to restart scheduler processes; recovery is a daemon restart, not a node reboot.
References
Related entries
- LightLLM: unbounded key-value writes on the NCCL control channel exhaust worker memoryCVE-2026-103042 · LightLLM NCCL KV-transfer control channel (exposed_set_value)High
- KubeAI (Ollama engine controller): Injection in `ollamaStartupProbeScript()`CVE-2026-34940 · KubeAI (Ollama engine controller)High
- Xinference: model launch API executes attacker-supplied Python because trust_remote_code is always onCVE-2026-76841 · Xinference (Xorbits Inference) model loaders - trust_remote_codeHigh
- Ollama: model pull follows cross-host redirects, giving SSRF to internal and metadata endpointsCVE-2026-85180 · Ollama (tensor-layer blob download, cross-host redirect handling)High
- Axolotl: multipack patch loads Hugging Face base models with trust_remote_code=True, giving RCE on the training nodeCVE-2026-86169 · Axolotl (multipack patch path, trust_remote_code guard)High
- vLLM: rejected requests leak decode-worker metadata until the worker exhausts memoryCVE-2026-93436 · vLLM NIXL KV connector (decode-side metadata cleanup for rejected requests)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.