Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3064
  • PyPI/sglang
SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice 6 days ago
  • No fix available
  • Severity - 2.9 (Low)
PYSEC-2026-3062
  • PyPI/sglang
SGLang has an Improper Input Validation/Injection Issue 6 days ago
  • No fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-3063
  • PyPI/sglang
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization 6 days ago
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-1919
  • PyPI/sglang
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor 07 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-538
  • PyPI/sglang
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability 29 Jun
  • No fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-536
  • PyPI/sglang
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket 29 Jun
  • No fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-535
  • PyPI/sglang
SGLang: Unauthenticated RCE via --enable-custom-logit-processor 29 Jun
  • No fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-539
  • PyPI/sglang
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker 29 Jun
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-537
  • PyPI/sglang
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module 29 Jun
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-m2jr-x4gq-5rmj
  • PyPI/sglang
SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice 02 Jun
  • No fix available
  • Severity - 2.9 (Low)
GHSA-36m8-w8qf-g76p
  • PyPI/sglang
SGLang: Unauthenticated RCE via --enable-custom-logit-processor 18 May
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-gwv6-pq6m-p3rq
  • PyPI/sglang
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket 18 May
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-qwrp-wghp-94q2
  • PyPI/sglang
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability 18 May
  • No fix available
  • Severity - 9.1 (Critical)
GHSA-6m5f-673f-5vh7
  • PyPI/sglang
SGLang has an Improper Input Validation/Injection Issue 03 May
  • No fix available
  • Severity - 6.3 (Medium)
GHSA-hvwj-8w5g-28rg
  • PyPI/sglang
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization 12 Mar
  • Fix available
  • Severity - 7.8 (High)
GHSA-jx93-g359-86wm
  • PyPI/sglang
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module 12 Mar
  • Fix available
  • Severity - 9.8 (Critical)