Vulnerabilities & PatchesEmerging1 src
VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem
Overview
A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service.
No patch is available at this time, and no response was obtained from the project maintainers during coordination. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs.
A vulnerability has been discovered within the tool and is tracked as follows: CVE-2026-14890 The vulnerability is caused by the ZeroMQ PULL socket in expert_backup_manager.
CVE-2026-14890CVE-2026-7301CVE-2026-7304