Skip to content
SGLangGHSA-jrcc-j37m-v8fg

SGLang is Vulnerable to DoS via the data_hash Function

Low3.6CVE-2026-10775 · Published Jun 4, 2026 · updated Aug 19, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
<= 0.5.11No fix yet
Details and references

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-404
Also known as
CVE-2026-10775, PYSEC-2026-3695

More SGLang advisories

All SGLang
DateAdvisory
Jun 2SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-10300Low3.7no fix yet
May 18SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7304Critical9.8no fix yet
May 18SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7301Critical9.8no fix yet
May 18SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7302Critical9.1no fix yet
May 3SGLang has an Improper Input Validation/Injection Issue
CVE-2026-7669Medium5.6no fix yet
Mar 12SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-3989High7.8fixed in 0.5.10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.