sglang
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sglangpage 1 of 1
- CVE-2025-10164HIGHCVSS 7.3EG 7.3✓ Fixed in 0.5.42025-09-09
vulnerable: 0.1.10 ... 0.5.3rc2 (126 versions)
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of the argument serialized_named_tensors results in deserialization. T…
- CVE-2026-3059CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.5.102026-03-12
vulnerable: 0.1.10 ... 0.5.9 (142 versions)
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3060CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.5.102026-03-12
vulnerable: 0.1.10 ... 0.5.9 (142 versions)
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3989HIGHCVSS 7.8EG 7.8✓ Fixed in 0.5.102026-03-12
vulnerable: 0.1.10 ... 0.5.9 (142 versions)
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the devi…
- CVE-2026-7669MEDIUMCVSS 5.6EG 5.62026-05-02
vulnerable: 0.1.10 ... 0.5.9 (141 versions)
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the a…
Check whether sglang is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sglang CVEs against the assets you own.
Start Free Scan →