CVE-2026-93034
CVE-2026-93034
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.
| Vendor | sglang |
| Product | sglang |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for sglang sglang
Be the first to know when new unknown vulnerabilities affecting sglang sglang are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SGLang / SGLang
0 โค v0.5.20