Every CVE whose affected-product data names Lmsys Sglang, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (15)
CVE-2026-5760 — CVSS 9.8 (critical): SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious…
CVE-2026-7301 — CVSS 9.8 (critical): SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads()…
CVE-2026-15969 — CVSS 9.8 (critical): SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing…
CVE-2026-15971 — CVSS 9.8 (critical): SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT…
CVE-2026-7304 — CVSS 9.8 (critical): SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor…
CVE-2026-15976 — CVSS 9.8 (critical): SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the…
CVE-2026-3059 — CVSS 9.8 (critical): SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes…
CVE-2026-3060 — CVSS 9.8 (critical): SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module…
CVE-2026-14890 — CVSS 9.1 (critical): SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain…
CVE-2026-7302 — CVSS 9.1 (critical): SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write…
CVE-2026-3989 — CVSS 7.8 (high): SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take…
CVE-2026-15978 — CVSS 7.5 (high): SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a…
CVE-2026-15977 — CVSS 7.5 (high): SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information…
CVE-2026-15974 — CVSS 6.5 (medium): SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url…
CVE-2026-10775 — CVSS 3.6 (low): A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the…