sglang vulnerabilities
CVEs whose affected-version data names the sglang package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-93838Medium· 5.9PoCSGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments
SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …
CVE-2026-93688High· 7.5SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's …
CVE-2026-92972High· 8.6SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table
SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary ra…
CVE-2026-86793Critical· 9.8PoCSGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…
SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…
CVE-2026-10775Low· 3.6SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-10300Low· 3.7SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-7669Medium· 5.6PoCSGLang has an Improper Input Validation/Injection Issue
SGLang has an Improper Input Validation/Injection Issue
CVE-2026-3989High· 7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2025-10164High· 7.3SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor