SGLang
3 known vulnerabilities in SGLang, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-94570 CVSS 5.9 medium SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which…
- CVE-2026-93088 CVSS 9.8 critical SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion…
- CVE-2026-86793 CVSS 9.8 critical SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the…