CVE-2026-5760 PUBLISHED

CVE-2026-5760

Assigner: certcc
Reserved: 07.04.2026 Published: 20.04.2026 Updated: 20.04.2026

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

Product Status

Vendor SGLang
Product SGLang
Versions
  • Version 0.59 is affected

References

Problem Types

  • CWE-94: Improper Control of Generation of Code ('Code Injection')