VYPR
Critical severity9.8NVD Advisory· Published Mar 12, 2026· Updated Apr 7, 2026

CVE-2026-3059

CVE-2026-3059

Description

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sglangPyPI
< 0.5.100.5.10

Affected products

1
  • cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:*
    Range: >=0.5.5,<=0.5.9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

2