CVE-2026-3059
EUVD-2026-1155712.03.2026, 12:15
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lmsys | sglang | 0.5.5 ≤ 𝑥 ≤ 0.5.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References