Skip to main content

Vendor/product archive

lmsys / sglang CVEs

Beta · best-effort

7 CVEs tagged to lmsys / sglang6 Critical, 0 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-10775

Published Jun 3, 2026

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation cause…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-7304

Published May 18, 2026

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded v…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-7302

Published May 18, 2026

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process h…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-7301

Published May 18, 2026

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when e…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-5760

Published Apr 20, 2026

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templat…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-3060

Published Mar 12, 2026

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pi…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-3059

Published Mar 12, 2026

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1