sglang
SGLang is a high-performance serving framework for large language models and multimodal models.
Activity
- Latest release
- 1w ago
- Total releases
- 156
- Cadence
- ~5 days
- Last 12 months
- 35
Reach
- Stars
- 36.0k
Details
- License
- custom
- First release
- Jan 16, 2024
| Version | Released | |
|---|---|---|
0.5.19
patch
| ||
0.5.18
patch
| ||
0.5.17
patch
| ||
0.5.16
patch
| ||
0.5.15.post1
pre
| ||
0.5.15
patch
| ||
0.5.14
patch
| ||
0.5.13.post1
pre
| ||
0.5.13
patch
| ||
0.5.12.post1
pre
3 CVEs
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.12
patch
3 CVEs
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.11
patch
4 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.10.post1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.10
patch
5 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.10rc0
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.9
patch
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.8.post1
pre
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.8
patch
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.7
patch
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.6.post2
pre
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.6.post1
pre
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.6
patch
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.5.post3
pre
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.5.post2
pre
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.5.post1
pre
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.5
patch
9 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7302
PYSEC-2026-538
GHSA-qwrp-wghp-94q2
Jun 29, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SGLang's multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7301
PYSEC-2026-536
GHSA-gwv6-pq6m-p3rq
Jun 29, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Affected versions
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
+ 4 more Show less
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.4.post3
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.4.post2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.4.post1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.4
patch
7 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.3.post3
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.3.post2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.3.post1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.3
patch
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.3rc2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.3rc0
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.2
patch
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.2rc2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.2rc1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.2rc0
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.1.post3
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.1.post2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.1.post1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.1
minor
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0rc2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0rc1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0rc0
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.10.post2
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.10.post1
pre
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.10
patch
8 CVEs
CVE-2026-10775
PYSEC-2026-3695
GHSA-jrcc-j37m-v8fg
Aug 19, 2026
SGLang is Vulnerable to DoS via the data_hash Function
Medium
Local
High
Low
None
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 133 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-10300
PYSEC-2026-3064
GHSA-m2jr-x4gq-5rmj
Jul 13, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Medium
Network
High
None
None
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 132 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-7669
PYSEC-2026-3062
GHSA-6m5f-673f-5vh7
Jul 13, 2026
SGLang has an Improper Input Validation/Injection Issue
Medium
Network
High
None
None
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 129 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3989
PYSEC-2026-3063
GHSA-hvwj-8w5g-28rg
Jul 13, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
SGLangs Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-10164
PYSEC-2026-1919
GHSA-9w53-xr52-mwgj
Jul 07, 2026
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Medium
Network
Low
None
None
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 114 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
Fixed in
0.5.4
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7304
PYSEC-2026-535
GHSA-36m8-w8qf-g76p
Jun 29, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Affected versions
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
+ 65 more Show less
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10
0.5.10.post1
0.5.10rc0
0.5.11
0.5.12
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-3059
PYSEC-2026-539
GHSA-3cp7-c6q2-94xr
GHSA-rgq9-fqf5-fv58
Jun 29, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-3060
PYSEC-2026-537
GHSA-jx93-g359-86wm
Jun 29, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. Affected versions
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.20
0.1.21
+ 130 more Show less
0.1.22
0.1.24
0.1.25
0.1.26
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.9
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.14.post1
0.2.14.post2
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.2.9.post1
0.3.0
0.3.1
0.3.1.post1
0.3.1.post2
0.3.1.post3
0.3.2
0.3.3
0.3.3.post1
0.3.4
0.3.4.post1
0.3.4.post2
0.3.5
0.3.5.post1
0.3.5.post2
0.3.6
0.3.6.post1
0.3.6.post2
0.3.6.post3
0.4.0
0.4.0.post1
0.4.0.post2
0.4.1
0.4.1.post1
0.4.1.post2
0.4.1.post3
0.4.1.post4
0.4.1.post5
0.4.1.post6
0.4.1.post7
0.4.10
0.4.10.post1
0.4.10.post2
0.4.2
0.4.2.post1
0.4.2.post2
0.4.2.post3
0.4.2.post4
0.4.3
0.4.3.post1
0.4.3.post2
0.4.3.post3
0.4.3.post4
0.4.4
0.4.4.post1
0.4.4.post2
0.4.4.post3
0.4.4.post4
0.4.5
0.4.5.post1
0.4.5.post2
0.4.5.post3
0.4.6
0.4.6.post1
0.4.6.post2
0.4.6.post3
0.4.6.post4
0.4.6.post5
0.4.7
0.4.7.post1
0.4.8
0.4.8.post1
0.4.9
0.4.9.post1
0.4.9.post2
0.4.9.post3
0.4.9.post4
0.4.9.post5
0.4.9.post6
0.5.0rc0
0.5.0rc1
0.5.0rc2
0.5.1
0.5.1.post1
0.5.1.post2
0.5.1.post3
0.5.10rc0
0.5.2
0.5.2rc0
0.5.2rc1
0.5.2rc2
0.5.3
0.5.3.post1
0.5.3.post2
0.5.3.post3
0.5.3rc0
0.5.3rc2
0.5.4
0.5.4.post1
0.5.4.post2
0.5.4.post3
0.5.5
0.5.5.post1
0.5.5.post2
0.5.5.post3
0.5.6
0.5.6.post1
0.5.6.post2
0.5.7
0.5.8
0.5.8.post1
0.5.9
Fixed in
0.5.10
References
Updated Jul 13, 2026 · Source: OSV.dev |