Deserialization Vulnerability in SGLang by sgl-project
CVE-2026-7669
6.3MEDIUM
What is CVE-2026-7669?
A deserialization vulnerability exists in the SGLang component of sgl-project, specifically within the get_tokenizer function in the HuggingFace Transformer Handler. This flaw allows attackers to manipulate data remotely, potentially leading to unauthorized access or data corruption. The vulnerability resides in the python/sglang/srt/utils/hf_transformers_utils.py file and affects versions up to 0.5.9. Exploiting this vulnerability requires a high level of complexity, making it more challenging for attackers. Despite early notifications to the vendor, no response has been received.
Affected Version(s)
SGLang 0.5.0
SGLang 0.5.1
SGLang 0.5.2
