Skip to content
SGLangGHSA-gwv6-pq6m-p3rq

SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket

Critical9.8CVE-2026-7301 · Published May 18, 2026 · updated Jun 29, 2026

SGLang's multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
>= 0.5.5, <= 0.5.12No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2026-7301, PYSEC-2026-536

More SGLang advisories

All SGLang
Advisory
SGLang is Vulnerable to DoS via the data_hash Function
Low3.6Jun 4
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Low3.7Jun 2
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
Critical9.8May 18
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
Critical9.1May 18
SGLang has an Improper Input Validation/Injection Issue
Medium5.6May 3
SGLang: unsafe deserialization
High7.8Mar 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.