CVE-2026-86793
N/A
N/A
Summary
SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SGLang | SGLang | 0 <= 0.5.18 | affected |
Weaknesses
- CWE-94 Improper Control of Generation of Code ('Code Injection')
References
- https://vicone.com/blog/cve-2026-86793-sglang-bypass-could-let-attackers-run-code-on-ai-servers/
- https://github.com/sgl-project/sglang/tree/main
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.