CVE-2026-3060
EUVD-2026-1155912.03.2026, 12:15
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lmsys | sglang | 0.5.5 ≤ 𝑥 ≤ 0.5.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration