Executive brief
SGLang is a framework for serving large language models. When deployed with disaggregated Prefill and Decode workers using the Mooncake transfer backend, an attacker with network access to the internal Decode control socket can send malformed messages that crash the control thread, preventing inference requests from completing. The HTTP health endpoint remains responsive, masking the failure from monitoring systems.
Technical details
Missing bounds validation on the buffer_index parameter in AUX_DATA ZeroMQ multipart messages allows an unauthenticated network peer to trigger an uncaught IndexError in the Decode worker's control-receive thread. The vulnerability is triggered when AuxDataCodec.deserialize_data_to_buffer() accesses kv_args.aux_data_ptrs with an out-of-range index, terminating the long-lived thread without recovery. Exploitation requires network reachability to the Decode worker's dynamically allocated ZeroMQ control PULL socket and is present in SGLang 0.5.15.post1 with Mooncake disaggregation enabled.
Affected products
- SGLang SGLang 0.5.15.post1 and possibly other versions with Mooncake disaggregation
Timeline
- 2026-09-22: disclosed