SGLangGHSA-6m5f-673f-5vh7
SGLang has an Improper Input Validation/Injection Issue
Medium5.6CVE-2026-7669 · Published May 3, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| sglang PyPI | <= 0.5.9 | No fix yet |
Details and references
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way.
More SGLang advisories
All SGLang| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 18 | SGLang: Unauthenticated RCE via --enable-custom-logit-processor CVE-2026-7304Critical9.8no fix yet | Critical9.8 | No fix yet |
| May 18 | SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket CVE-2026-7301Critical9.8no fix yet | Critical9.8 | No fix yet |
| May 18 | SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability CVE-2026-7302Critical9.1no fix yet | Critical9.1 | No fix yet |
| Jun 2 | SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice CVE-2026-10300Low3.7no fix yet | Low3.7 | No fix yet |
| Jun 4 | SGLang is Vulnerable to DoS via the data_hash Function CVE-2026-10775Low3.6no fix yet | Low3.6 | No fix yet |
| Mar 12 | SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization CVE-2026-3989High7.8fixed in 0.5.10 | High7.8 | 0.5.10 |