Sceawere
Vulnerability Detail
CVE-2026-102634UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SGLang Mooncake KV Race Condition
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 8h ago
- Vendor
- sgl-project
- Product
- sglang
- Attack Type
- Use of Multiple Resources with Duplicate Identifier
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-29T17:17:07.147Z",
"pubdate": "2026-09-29T17:17:07.147Z",
"executiveSummary": "A critical race condition vulnerability exists in SGLang versions through 0.5.20 when operating in prefill/decode disaggregation mode with the Mooncake KV transfer backend. The vulnerability arises from a lack of validation regarding duplicate 'bootstrap_room' identifiers in '/generate' API requests.\nUnauthenticated remote attackers can leverage this flaw to trigger internal state inconsistencies within the scheduler process. By submitting concurrent, conflicting requests utilizing identical 'bootstrap_room' values, an attacker can induce resource contention that leads to process crashes or persistent request blocking for legitimate users.\nThe impact includes a potential Denial of Service (DoS) condition, disrupting inference services and causing significant availability degradation. The vulnerability is exploitable over the network without requiring prior authentication, making it a high-risk security concern for distributed SGLang deployments utilizing Mooncake for KV cache migration.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient synchronization and input validation logic within the Mooncake KV transfer backend, specifically concerning the handling of the 'bootstrap_room' parameter. In the prefill/decode disaggregation architecture, the 'bootstrap_room' field is intended to act as a unique identifier for KV cache memory segments being transferred between nodes.\nWhen a '/generate' request is processed, the system initiates a transfer sequence. If the system receives multiple concurrent requests sharing the same 'bootstrap_room' identifier, the backend fails to implement a locking mechanism or check for existing transfers associated with that room ID. This state results in a race condition where multiple threads attempt to manage, initialize, or clear the same memory buffer simultaneously.\nThe attack flow begins with an unauthenticated actor crafting multiple HTTP POST requests to the '/generate' endpoint, deliberately injecting duplicate 'bootstrap_room' values into the request payload. Upon processing these requests, the scheduler attempts to manage the KV cache transfer using conflicting metadata. This contention manifests in several ways: firstly, the scheduler process may encounter unhandled exceptions, leading to an immediate crash. Secondly, if the process does not terminate, the conflicting ownership of the 'bootstrap_room' resource causes the internal state machine to hang while waiting for a synchronization signal that will never arrive due to the corrupted state. Consequently, the request remains stuck, consuming worker slots and eventually timing out, effectively exhausting available resources.\nThe vulnerability is exposed through the API interface used for inference management. Because SGLang deployments often expose these endpoints to allow client interaction, the network exposure is significant. As the Mooncake backend operates during the critical path of prefill and decode disaggregation, exploitation directly targets the stability of the entire inference pipeline. Post-exploitation, the attacker successfully denies service to other users, as the scheduler's ability to process new or existing inference tasks is compromised until the affected processes are restarted and the memory state is cleared."
}