SGLangGHSA-36m8-w8qf-g76p
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
Critical9.8CVE-2026-7304 · Published May 18, 2026 · updated Jun 29, 2026
SGLang's multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| sglang PyPI | >= 0.4.1.post7, <= 0.5.12 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2026-7304, PYSEC-2026-535
More SGLang advisories
All SGLang| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 4 | SGLang is Vulnerable to DoS via the data_hash Function | Low3.6 | No fix yet |
| Jun 2 | SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice | Low3.7 | No fix yet |
| May 18 | SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket | Critical9.8 | No fix yet |
| May 18 | SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability | Critical9.1 | No fix yet |
| May 3 | SGLang has an Improper Input Validation/Injection Issue | Medium5.6 | No fix yet |
| Mar 12 | SGLang: unsafe deserialization | High7.8 | 0.5.10 |