Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sglang CRITICAL 9.8
CVE-2026-15969

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15971

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15976

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Sglang HIGH 7.5
CVE-2026-15977

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the…

Fix: after 0.5.15
Fix from $1,950 2026-07-30
Sglang HIGH 7.5
CVE-2026-15978

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote at…

Fix: after 0.5.15
Fix from $1,950 2026-07-30
Sglang MEDIUM 6.5
CVE-2026-15974

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access …

Fix: after 0.5.15
Fix from $1,600 2026-07-30
Sglang CRITICAL 9.1
CVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authenticatio…

Fix: after 0.5.14
Fix from $2,300 2026-07-16
Sglang MEDIUM 5.3
CVE-2026-10775

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Ha…

Fix: after 0.5.11
Fix from $1,600 2026-06-03
Sglang CRITICAL 9.8
CVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.8
CVE-2026-7304

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.1
CVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.8
CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load…

Fix: 0.5.11+
Fix from $2,300 2026-04-20
Sglang CRITICAL 9.8
CVE-2026-3059

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat…

Fix: after 0.5.9
Fix from $2,300 2026-03-12
Sglang CRITICAL 9.8
CVE-2026-3060

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri…

Fix: after 0.5.9
Fix from $2,300 2026-03-12
Sglang HIGH 7.8
CVE-2026-3989

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of …

Fix: 0.5.10+
Fix from $1,950 2026-03-12