Lmsys
Lmsys Sglang: vulnerabilidades y CVE
Lmsys Sglang tiene 25 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses24
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102634 | Alta (8.7) | 0.58% | — | 29 sept 2026 | SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent… |
| CVE-2026-94570 | Media (5.9) | 0.47% | — | 22 sept 2026 | SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode… |
| CVE-2026-93088 | Crítica (9.8) | 0.73% | — | 22 sept 2026 | SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a… |
| CVE-2026-93838 | Alta (8.2) | 0.65% | — | 18 sept 2026 | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments.… |
| CVE-2026-93688 | Alta (8.7) | 0.72% | — | 18 sept 2026 | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach… |
| CVE-2026-92972 | Alta (8.8) | 0.47% | — | 17 sept 2026 | SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can… |
| CVE-2026-86793 | Crítica (9.8) | 0.77% | — | 11 sept 2026 | SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are… |
| CVE-2026-15978 | Alta (7.5) | 0.50% | — | 30 jul 2026 | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then… |
| CVE-2026-15977 | Alta (7.5) | 0.41% | — | 30 jul 2026 | SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured. |
| CVE-2026-15976 | Crítica (9.8) | 0.60% | — | 30 jul 2026 | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables… |
| CVE-2026-15974 | Media (6.5) | 0.36% | — | 30 jul 2026 | SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services. |
| CVE-2026-15971 | Crítica (9.8) | 0.73% | — | 30 jul 2026 | SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. |
| CVE-2026-15969 | Crítica (9.8) | 1.0% | — | 30 jul 2026 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. |
| CVE-2026-14890 | Crítica (9.1) | 1.00% | — | 16 jul 2026 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a… |
| CVE-2026-10775 | Baja (1.1) | 0.12% | — | 3 jun 2026 | A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is… |
| CVE-2026-10300 | Baja (2.9) | 0.37% | — | 1 jun 2026 | A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the… |
| CVE-2026-7304 | Crítica (9.8) | 0.88% | — | 18 may 2026 | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized… |
| CVE-2026-7302 | Crítica (9.1) | 0.58% | — | 18 may 2026 | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../… |
| CVE-2026-7301 | Crítica (9.8) | 0.60% | — | 18 may 2026 | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. |
| CVE-2026-7669 | Media (6.3) | 0.42% | — | 2 may 2026 | A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The… |
| CVE-2026-5760 | Crítica (9.8) | 1.1% | — | 20 abr 2026 | SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed… |
| CVE-2026-3989 | Alta (7.8) | 0.43% | — | 12 mar 2026 | SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the… |
| CVE-2026-3060 | Crítica (9.8) | 1.3% | — | 12 mar 2026 | SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. |
| CVE-2026-3059 | Crítica (9.8) | 1.3% | — | 12 mar 2026 | SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. |
| CVE-2025-10164 | Media (5.5) | 0.40% | — | 9 sept 2025 | A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.