Remote Code Execution Vulnerability in SGLangs MultiModal Generation Runtime
CVE-2026-7304

9.8CRITICAL

Key Information:

Vendor

Sglang

Status
Vendor
CVE Published:
18 May 2026

What is CVE-2026-7304?

The SGLangs MultiModal Generation Runtime is susceptible to unauthenticated remote code execution due to improper handling of Python objects during the deserialization process. When the --enable-custom-logit-processor option is active, Python objects are deserialized without adequate validation, allowing potential attackers to execute arbitrary code on the server, posing significant risks to the integrity and confidentiality of the system.

Affected Version(s)

SGLang 5.10

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.