Answer in brief
CVE-2026-102634 records a High severity (CVSS 8.7) vulnerability in SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room. The current sources do not mark it as known exploited. The current feed maps sgl-project/sglang (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps sgl-project/sglang (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| sgl-project/sglanggeneric | >=0 <=0.5.20 | Not reported |
Published upstream
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 29, 2026
SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout.
Quoted source text, attributed separately from HOL analysis.