Vulnerabilities
Vulnerable Software
Lmsys:  >> Sglang  >> 0.5.10  Security Vulnerabilities
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
CVSS Score
9.8
EPSS Score
0.006
Published
2026-05-18
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().
CVSS Score
9.8
EPSS Score
0.009
Published
2026-04-20


Contact Us

Shodan ® - All rights reserved