sglang is vulnerable to Allocation of Resources Without Limits or Throttling
59
Medium Risk
In prefill/decode disaggregation deployments, handle_staging_req() does not validate the chunk_idx field carried in ZMQ STAGING_REQ frames. A peer with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value. This drives unbounded memory allocation in the scheduler until the process runs out of memory and terminates.
You are affected if you are using a version that falls within the vulnerable range and you run SGLang in prefill/decode disaggregation mode with the decode engine's internal ZMQ rank port reachable by untrusted peers.
sglang is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.1 - 0.5.20.
Upgrade the sglang library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.