Vulnerabilities
Vulnerable Software
Lmsys:  >> Sglang  >> 0.5.8  Security Vulnerabilities
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.
CVSS Score
9.8
EPSS Score
0.012
Published
2026-03-12
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-03-12


Contact Us

Shodan ® - All rights reserved