Remote Code Execution in SGLang Affects Security Practices
CVE-2026-15971
Currently unrated
What is CVE-2026-15971?
SGLang presents a Remote Code Execution vulnerability due to its optional dumper subsystem being enabled. When the DUMPER_SERVER_PORT is set, this configuration can result in a sandbox escape, permitting unauthorized code execution during inference requests. Organizations utilizing SGLang must assess their configurations and apply the recommended security patches to mitigate this risk.
Affected Version(s)
SGLang 0
