Skip to content
SGLangGHSA-m2jr-x4gq-5rmj

SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice

Low3.7CVE-2026-10300 · Published Jun 2, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
sglang
PyPI
<= 0.5.10.post1No fix yet
Details and references

A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-617
Also known as
CVE-2026-10300, PYSEC-2026-3064

More SGLang advisories

All SGLang
DateAdvisory
Jun 4SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-10775Low3.6no fix yet
May 18SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7304Critical9.8no fix yet
May 18SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7301Critical9.8no fix yet
May 18SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7302Critical9.1no fix yet
May 3SGLang has an Improper Input Validation/Injection Issue
CVE-2026-7669Medium5.6no fix yet
Mar 12SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-3989High7.8fixed in 0.5.10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.