ZeroHour

CVE-2026-3060

PoC
CVSS 3.1
9.8 critical
EPSS
1%p65
Published
()
Modified
Description

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.

Vendors
lmsys
Products
sglang
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news