VYPR
Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 31, 2026

CVE-2026-15969

CVE-2026-15969

Description

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

1