Back to overview

CVE-2026-3059

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

Metadata

CVE ID
CVE-2026-3059
State
PUBLISHED
Assigner
certcc
Reserved
2026-02-23 18:17 UTC
Published
2026-03-12 11:37 UTC
Last updated
2026-04-07 18:46 UTC
Primary CWE
CWE-502
CWE-502 Deserialization of Untrusted Data
Vendor / Product
SGLang / SGLang
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SGLang SGLang 0.5.10
Weakness (CWE)
CWESourceDescription
cna CWE-502: Deserialization of Untrusted Data
CWE-502 adp CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview