CVE-2026-7301 PUBLISHED

CVE-2026-7301

Assigner: certcc
Reserved: 28.04.2026 Published: 18.05.2026 Updated: 18.05.2026

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.

Product Status

Vendor SGLang
Product SGLang
Versions
  • Version 5.10 is affected

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data