A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
References
| Link | Resource |
|---|---|
| https://github.com/sgl-project/sglang/ | Product |
| https://github.com/sgl-project/sglang/issues/25462 | Issue Tracking |
| https://github.com/sgl-project/sglang/pull/22033 | Issue Tracking Patch |
| https://vuldb.com/cve/CVE-2026-10775 | Third Party Advisory VDB Entry |
| https://vuldb.com/submit/831438 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/368138 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/368138/cti | Permissions Required VDB Entry |
| https://github.com/sgl-project/sglang/pull/22033 | Issue Tracking Patch |
| https://vuldb.com/submit/831438 | Third Party Advisory VDB Entry |
Configurations
History
22 Jul 2026, 20:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 Jun 2026, 18:19
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:* | |
| First Time |
Lmsys
Lmsys sglang |
|
| References | () https://github.com/sgl-project/sglang/ - Product | |
| References | () https://github.com/sgl-project/sglang/issues/25462 - Issue Tracking | |
| References | () https://github.com/sgl-project/sglang/pull/22033 - Issue Tracking, Patch | |
| References | () https://vuldb.com/cve/CVE-2026-10775 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/submit/831438 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/368138 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/368138/cti - Permissions Required, VDB Entry |
04 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/sgl-project/sglang/pull/22033 - | |
| References | () https://vuldb.com/submit/831438 - |
03 Jun 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-03 23:16
Updated : 2026-07-22 20:10
NVD link : CVE-2026-10775
Mitre link : CVE-2026-10775
CVE.ORG link : CVE-2026-10775
JSON object : View
Products Affected
lmsys
- sglang
CWE
CWE-404
Improper Resource Shutdown or Release
