ZeroHour

CVE-2026-3059

PoC
CVSS 3.1
9.8 critical
EPSS
2%p73
Published
()
Modified
Description

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

Vendors
lmsys
Products
sglang
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news