CVE-2026-7304 PUBLISHED

CVE-2026-7304

Assigner: certcc
Reserved: 28.04.2026 Published: 18.05.2026 Updated: 18.05.2026

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.

Product Status

Vendor SGLang
Product SGLang
Versions
  • Version 5.10 is affected

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data