Critical severity9.1NVD Advisory· Published Jul 16, 2026· Updated Aug 10, 2026
CVE-2026-14890
CVE-2026-14890
Description
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- www.kb.cert.org/vuls/id/326070nvdMitigationThird Party Advisory
- vince.cert.org/vuls/id/326070nvdPermissions Required
- github.com/sgl-project/sglang/blob/main/python/sglang/srt/elastic_ep/expert_backup_manager.pynvdProduct
News mentions
0No linked articles in our index yet.