{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asglangsglang/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sglang:sglang:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-92972"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SGLang (\u003c= 0.5.19)"],"_cs_severities":["medium"],"_cs_tags":["sglang","routing-poisoning","cve-2026-92972","denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["SGLang"],"content_html":"\u003cp\u003eSGLang versions through 0.5.19 are vulnerable to a critical routing table poisoning flaw when operating in prefill/decode disaggregation mode. The prefill bootstrap service exposes an unauthenticated PUT /route endpoint, which lacks access controls, allowing unauthorized actors to inject arbitrary 'rank_ip' and 'rank_port' values into the internal KV transfer routing table. By manipulating this table, attackers can redirect traffic destined for decode workers to attacker-controlled infrastructure. Successful exploitation results in a denial-of-service condition for the affected model pipeline and the exfiltration of sensitive KV transfer metadata, including session identifiers and internal tensor-parallel topology parameters. This vulnerability is particularly impactful for distributed inference deployments relying on the disaggregated architecture of SGLang.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation enables attackers to intercept or disrupt model inference traffic. This can lead to the unauthorized disclosure of proprietary session metadata and internal topology information, as well as a complete denial of service for the disaggregated model inference cluster. The impact affects any organization utilizing SGLang in the specified disaggregation configuration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade SGLang to a version beyond 0.5.19 to address the unauthorized access to the routing configuration.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the SGLang prefill bootstrap service ports to known-trusted internal management IPs only.\u003c/li\u003e\n\u003cli\u003eAudit web access logs for PUT requests directed to the /route endpoint that originate from untrusted or external network segments.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected network connections from decode worker nodes to unknown or unauthorized destination IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T18:08:39Z","date_published":"2026-09-17T17:58:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sglang-route-poisoning/","summary":"SGLang versions up to 0.5.19 in disaggregation mode expose an unauthenticated PUT /route endpoint allowing remote attackers to poison KV transfer tables and redirect sensitive data.","title":"Unauthenticated Routing Table Poisoning in SGLang","url":"https://feed.craftedsignal.io/briefs/2026-09-sglang-route-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sglang:sglang:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}