CVE-2026-10775Low· 3.6▾ SunlitSGLang is Vulnerable to DoS via the data_hash Function
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.1%
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
sglang <= 0.5.11Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3989High· 7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-7669Medium· 5.6SGLang has an Improper Input Validation/Injection Issue
CVE-2026-10300Low· 3.7SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2025-10164High· 7.3SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
CVE-2026-93838Medium· 5.9SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments
CVE-2026-93688High· 7.5SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation