Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE
ID: d2e6061f-4342-5e6e-961a-1842e4e724f5
STIX ID: report--d2e6061f-4342-5e6e-961a-1842e4e724f5
Feed Name: securityonline.info
CERT/CC disclosed three critical vulnerabilities in the SGLang multimodal AI serving framework: CVE-2026-7301 and CVE-2026-7304 enable unauthenticated remote code execution through insecure deserialization (pickle/dill), and CVE-2026-7302 permits unauthenticated path traversal during media uploads; the scheduler binds to 0.0.0.0 by default, no patch or maintainer response is available, and the advisory urges immediate mitigations (bind to loopback/private addresses, restrict network access, disable the custom logit processor).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
