VYPR
Critical severity9.8NVD Advisory· Published Mar 12, 2026· Updated Apr 7, 2026

CVE-2026-3060

CVE-2026-3060

Description

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sglangPyPI
< 0.5.100.5.10

Affected products

1
  • cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:*
    Range: >=0.5.5,<=0.5.9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

2