Skip to content
SGLangGHSA-hvwj-8w5g-28rg

SGLang: unsafe deserialization

High7.8CVE-2026-3989 · Published Mar 12, 2026 · updated Jul 13, 2026

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
< 0.5.100.5.10
Details and references

More SGLang advisories

All SGLang
Advisory
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
Critical9.1May 18
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
Critical9.8May 18
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
Critical9.8May 18
SGLang has an Improper Input Validation/Injection Issue
Medium5.6May 3
SGLang: remote code execution
Critical9.8Mar 12
SGLang: remote code execution
Critical9.8Mar 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.