Deserialization Vulnerability in SGLang by sgl-project
CVE-2026-7669
Key Information:
- Vendor
Sgl-project
- Status
- Vendor
- CVE Published:
- 2 May 2026
Badges
What is CVE-2026-7669?
A deserialization vulnerability exists in the SGLang component of sgl-project, specifically within the get_tokenizer function in the HuggingFace Transformer Handler. This flaw allows attackers to manipulate data remotely, potentially leading to unauthorized access or data corruption. The vulnerability resides in the python/sglang/srt/utils/hf_transformers_utils.py file and affects versions up to 0.5.9. Exploiting this vulnerability requires a high level of complexity, making it more challenging for attackers. Despite early notifications to the vendor, no response has been received.
Affected Version(s)
SGLang 0.5.0
SGLang 0.5.1
SGLang 0.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
