SGLang has 8 CVEs on record between 2025 and 2026. Cadence is steady at roughly 3 per quarter. The busiest recent month was September 2026 with 3. The median CVSS is 5.9 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 3 prev 3
Weakness classes
Products
- SGLang 8
Worst active — by depth score
CVE-2026-86793Critical· 9.8SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…66CVE-2026-7669Medium· 5.6SGLang has an Improper Input Validation/Injection Issue43CVE-2026-3989High· 7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization43CVE-2025-10164High· 7.3SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor40CVE-2026-94570Medium· 5.9SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socke…32
SGLang vulnerabilities
CVEs affecting SGLang, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-93088NoneSGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …
CVE-2026-94570Medium· 5.9SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socke…
SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socke…
CVE-2026-86793Critical· 9.8PoCSGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…
SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…
CVE-2026-10775Low· 3.6SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-10300Low· 3.7SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-7669Medium· 5.6PoCSGLang has an Improper Input Validation/Injection Issue
SGLang has an Improper Input Validation/Injection Issue
CVE-2026-3989High· 7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2025-10164High· 7.3SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor