logo

Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE

ID: d2e6061f-4342-5e6e-961a-1842e4e724f5

STIX ID: report--d2e6061f-4342-5e6e-961a-1842e4e724f5

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

CERT/CC disclosed three critical vulnerabilities in the SGLang multimodal AI serving framework: CVE-2026-7301 and CVE-2026-7304 enable unauthenticated remote code execution through insecure deserialization (pickle/dill), and CVE-2026-7302 permits unauthenticated path traversal during media uploads; the scheduler binds to 0.0.0.0 by default, no patch or maintainer response is available, and the advisory urges immediate mitigations (bind to loopback/private addresses, restrict network access, disable the custom logit processor).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.