PYSEC-2026-3695

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/sglang/PYSEC-2026-3695.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3695
Aliases
Published
2026-08-19T11:56:24.847653Z
Modified
2026-08-19T12:45:06.857032943Z
Severity
  • 3.6 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
SGLang is Vulnerable to DoS via the data_hash Function
Details

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

References

Affected packages

PyPI / sglang

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.5.11

Affected versions

0.*
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
0.1.22
0.1.24
0.1.25
0.1.26
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.4.10
0.4.10.post1
0.4.10.post2
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.2
0.5.3rc0
0.5.3rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
0.5.10rc0
0.5.10
0.5.10.post1
0.5.11

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/sglang/PYSEC-2026-3695.yaml"