Search
Search Results (8 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15978 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-08-04 | 7.5 High |
| SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights. | ||||
| CVE-2026-15971 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-08-02 | 9.8 Critical |
| SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. | ||||
| CVE-2026-15976 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-07-31 | 9.8 Critical |
| SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files. | ||||
| CVE-2026-15974 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-07-31 | 6.5 Medium |
| SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services. | ||||
| CVE-2026-15977 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-07-31 | 7.5 High |
| SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured. | ||||
| CVE-2026-15969 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-07-31 | 9.8 Critical |
| SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. | ||||
| CVE-2026-14890 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-07-16 | 9.1 Critical |
| SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network. | ||||
| CVE-2026-3989 | 2 Lmsys, Sglang | 2 Sglang, Sglang | 2026-04-07 | 7.8 High |
| SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script. | ||||
Page 1 of 1.