Pickle Deserialization Vulnerability in SGLang by Vicon
CVE-2026-86793
Currently unrated
What is CVE-2026-86793?
The SGLang software has a critical security flaw that allows unauthenticated users to exploit a pickle deserialization issue via the /update_weights_from_tensor endpoint. This occurs when authentication keys are not implemented, thus bypassing SafeUnpickler policies. Attackers can leverage builtins.import and builtins.getattr to execute arbitrary code on vulnerabilities within the system, posing significant risks to application integrity and data security.
Affected Version(s)
SGLang 0 <= 0.5.18
