SGLang 在 0.5.19 及更早版本中,当启用 prefill/decode 分离模式时,其 prefill 引导服务(bootstrap service)中存在一个未认证的 端点。攻击者可以利用该漏洞污染 KV 缓存传输的路由表。通过提供任意的 和 值,攻击者可以将 decode 工作进程重定向到由攻击者控制的端点,从而导致拒绝服务(DoS)或泄露 KV 缓存传输相关的元数据,例如会话标识符和 tensor-parallel(张量并行)拓扑参数。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sgl-project | sglang | 0 ~ 0.5.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet