Vulnerabilities
Vulnerable Software
Lmsys:  >> Sglang  >> 0.1.21  Security Vulnerabilities
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
CVSS Score
1.1
EPSS Score
0.0
Published
2026-06-03
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().
CVSS Score
9.8
EPSS Score
0.006
Published
2026-04-20


Contact Us

Shodan ® - All rights reserved