logo

The Poisoned Pickle: Critical Unpatched RCE Flaws Expose SGLang AI Infrastructure

ID: a1073957-14d4-5ae5-a247-732d67da6b3c

STIX ID: report--a1073957-14d4-5ae5-a247-732d67da6b3c

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed critical unsafe-serialization vulnerabilities in the SGLang LLM serving framework—two high-severity RCE issues (CVE-2026-3059, CVE-2026-3060) via malicious pickle deserialization over ZeroMQ, plus a replay-tool vulnerability (CVE-2026-3989) that can execute attacker-supplied crash dumps; maintainers reportedly have not yet responded and mitigations recommended include isolating ZeroMQ interfaces, network segmentation, and replacing pickle with safe serialization formats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.