Skip to content

SGLang security advisories

10 advisories · 6 critical or high in 12 months · latest Jun 4

10 advisories

DateAdvisory
Jun 4SGLang is Vulnerable to DoS via the data_hash Function
CVE-2026-10775Low3.6no fix yet
Jun 2SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-10300Low3.7no fix yet
May 18SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7304Critical9.8no fix yet
May 18SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7301Critical9.8no fix yet
May 18SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7302Critical9.1no fix yet
May 3SGLang has an Improper Input Validation/Injection Issue
CVE-2026-7669Medium5.6no fix yet
Mar 12SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-3989High7.8fixed in 0.5.10
Mar 12SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
CVE-2026-3060Critical9.8fixed in 0.5.10
Mar 12SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
CVE-2026-3059Critical9.8fixed in 0.5.10
Sep 92025SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
CVE-2025-10164Medium7.3fixed in 0.5.4
About SGLang

The fast serving framework for LLMs and vision models.

Packages watched: sglang (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.