Skip to content
SGLangGHSA-6m5f-673f-5vh7

SGLang has an Improper Input Validation/Injection Issue

Medium5.6CVE-2026-7669 · Published May 3, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
<= 0.5.9No fix yet
Details and references

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-74
Also known as
CVE-2026-7669, PYSEC-2026-3062

More SGLang advisories

All SGLang
DateAdvisory
May 18SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7304Critical9.8no fix yet
May 18SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7301Critical9.8no fix yet
May 18SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7302Critical9.1no fix yet
Jun 2SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-10300Low3.7no fix yet
Jun 4SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-10775Low3.6no fix yet
Mar 12SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-3989High7.8fixed in 0.5.10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.