CVE Vulnerabilities

CVE-2026-102634

Use of Multiple Resources with Duplicate Identifier

Published: Sep 29, 2026 | Modified: Sep 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users requests until transfer timeout.

Weakness

The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.

Potential Mitigations

References