Known Vulnerabilities for SGLang by Sgl-project
Listed below are 10 of the newest known vulnerabilities associated with "SGLang" by "Sgl-project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94570 json | SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode wor... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-93838 json | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to val... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-93688 json | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_roo... | Not Provided | 2026-09-18 | 2026-09-21 |
| CVE-2026-93088 json | SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-di... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-92972 json | SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bo... | Not Provided | 2026-09-17 | 2026-09-18 |
| CVE-2026-86793 json | SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, an... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-61732 json | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of ag... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-15978 json | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoint... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-15977 json | SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile i... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-15976 json | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within ... | Not Provided | 2026-07-30 | 2026-07-31 |