VulnSea

sglang has 6 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 6.4 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
Last 90 days
1 prev 3

Weakness classes

Products

  • SGLang 6
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

sglang vulnerabilities

CVEs affecting sglang, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-86793Critical· 9.8PoC
1w ago

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

AbyssalSGLang · SGLangEPSS 0.43%via NVD
CVE-2026-10775Low· 3.6
3mo ago

SGLang is Vulnerable to DoS via the data_hash Function

SGLang is Vulnerable to DoS via the data_hash Function

Sunlitsglang · sglangEPSS 0.12%via OSV
CVE-2026-10300Low· 3.7
3mo ago

SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice

SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice

Sunlitsglang · sglangEPSS 0.37%via OSV
CVE-2026-7669Medium· 5.6PoC
4mo ago

SGLang has an Improper Input Validation/Injection Issue

SGLang has an Improper Input Validation/Injection Issue

Twilightsglang · sglangEPSS 0.37%via OSV
CVE-2026-3989High· 7.8
6mo ago

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization

Twilightsglang · sglangEPSS 0.47%via OSV
CVE-2025-10164High· 7.3
1y ago

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

Twilightsglang · sglangEPSS 0.40%via OSV
sglang vulnerabilities (CVEs) · VulnSea