CVE-2026-10300 PUBLISHED

SGLang Inference HTTP Endpoint lora_manager.py assertion

Assigner: VulDB
Reserved: 31.05.2026 Published: 01.06.2026 Updated: 02.06.2026

A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.3

Product Status

Vendor n/a
Product SGLang
Versions
  • Version 0.5.10.post1 is affected

Credits

  • Zyz3366 (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Reachable Assertion CWE