logo

CVE-2026-14890: SGLang ZeroMQ Unauthenticated RCE via Pickle Deserialization

ID: c19ba5d8-c5eb-581d-9376-7ec9c53d51f4

STIX ID: report--c19ba5d8-c5eb-581d-9376-7ec9c53d51f4

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

**CVE-2026-14890 — SGLang insecure deserialization RCE:** A critical (CVSS 9.1) remote code execution vulnerability exists in SGLang's expert-parallel subsystem where an unauthenticated ZeroMQ PULL socket bound to a routable interface deserializes attacker-controlled Python pickle objects, allowing full code execution; the advisory describes the attack vector, affected configurations, and mitigations (firewalling the port, binding to loopback, network controls) but notes no patch referenced in the NVD at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.