SGLang LLM Serving Framework has a CVSS 9.8 vulnerability
2026-10-09 17:30:53
According to CoinMeta, as reported by Forkast, SGLang LLM Serving Framework has a pickle deserialization remote code execution (RCE) vulnerability with a severity of 9.8, which still exists even when pickle is disabled. Research indicates that this vulnerability allows for unauthorized remote code execution and can be exploited remotely when the data parallel attention mechanism is configured in a non-looping mode. The vulnerability has been assigned the identifier CVE-2026-93034, and there is currently no fix available for it.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.