Skip to content
SGLangGHSA-jx93-g359-86wm

SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module

Critical9.8CVE-2026-3060 · Published Mar 12, 2026 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
< 0.5.100.5.10
Details and references

SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2026-3060, PYSEC-2026-537

More SGLang advisories

All SGLang
DateAdvisory
Mar 12SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-3989High7.8fixed in 0.5.10
Mar 12SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
CVE-2026-3059Critical9.8fixed in 0.5.10
May 3SGLang has an Improper Input Validation/Injection Issue
CVE-2026-7669Medium5.6no fix yet
May 18SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7304Critical9.8no fix yet
May 18SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7301Critical9.8no fix yet
May 18SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7302Critical9.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.