SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93838.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.5.20"
},
{
"fixed": "0.5.20"
}
],
"source": [
"AFFECTED_FIELD",
"DESCRIPTION"
]
}