CVE-2026-3059Disclosure(lmsys / sglang)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch lmsys sglang systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sglang

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-17); latest day: 1
  • 9 total mentions across 8 days

Affected systems

Vendors
Products
sglang

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 2Mentions · 2026-04-09: 1Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Mentions · 2026-04-21: 1Active Exploitation · 2026-04-21: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-21: 103-1203-1303-1603-1704-0904-1604-1704-21
Signal classification4 categories
Disclosure
555.6%
General
222.2%
Patch
111.1%
Active Exploitation
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-161
Disclosure1
2026-03-172
Disclosure2
2026-04-091
Patch1
2026-04-161
General1
2026-04-171
General1
2026-04-211
Active Exploitation1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Critical 9.8 CVSS unpatched RCE flaws in the SGLang AI framework (CVE-2026-3059 & CVE-2026-3060) expose servers via unsafe Python pickle deserialization. #SGLang #AISecurity #PickleDeserialization #CVE #LLMSecurity #CyberSecurity #InfoSec #RCE #ZeroDay https://securityonline.info/poisoned-pickle-critical-unpatched-rce-flaws-sglang-ai-infrastructure/ https://t.co/ZAln4BRyXc

    Post summary

    The tweet announces two unpatched RCE vulnerabilities (CVE‑2026‑3059 & CVE‑2026‑3060) in the SGLang AI framework, highlighting high severity (CVSS 9.8) and unsafe pickle deserialization, but provides neither PoC, exploit code, active exploitation claims nor patch information.

    02041456
    10.7K followersView on X
  • O Pantera Negra · IA & Produto 🤖@opanteranegra77
    General

    SGLang RadixAttention vence benchmarks (29% mais rápido), mas CVE-2026-3059 é RCE unauthenticada na multimodal. Testei: infrastructure attack surface > performance gains. Otimização sem segurança = piscina com hiena. #IA #PromptEngineering

    Post summary

    The post confirms CVE-2026-3059 as an unauthenticated RCE, but does not provide a PoC, exploit, active exploitation evidence, or patch information.

    3000037
    232 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    The other two (CVE-2026-3059, 3060): pickle deserialization over the network. Pre-auth. No credentials needed. Just send a crafted payload. No patch for these either. SentinelLabs says: unexpected outbound connections from SGLang workers = you've already been hit.

    Post summary

    CVE-2026-3059 and 3060 allow pre‑auth pickle deserialization over the network; SentinelLabs reports remote exploitation via unexpected outbound connections from SGLang workers, with no patches or workarounds available.

    1000027
    1 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2018-17144 2 - CVE-2026-34621 3 - CVE-2010-5139 4 - CVE-2026-32201 5 - CVE-2026-3059 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVEs as trending without providing any further details, claims, or technical information.

    00010148
    1.7K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `SGLang`'s multimodal generation module is vulnerable to unauthenticated RCE via the ZMQ broker (CVE-2026-3059). Restrict network access to the ZMQ port and monitor for a fix. #SGLang #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-3059-sglang-rce-zmq-broker

    Post summary

    SGLang’s multimodal generation module has an unauthenticated RCE (CVE‑2026‑3059); restricting access to the ZMQ port is advised while vendors address the issue.

    0000042
    11 followersView on X
  • SH TC@shtc_social
    Disclosure

    🚨 Amazon Bedrock, LangSmith ve SGLang'de Kritik AI Güvenlik Açıkları! DNS sorguları ile veri sızdırma ve RCE saldırıları mümkün. CVE-2026-3059/3060 (CVSS 9.8) kritik! #SiberGüvenlik #AI #AmazonBedrock #LangSmith #SGLang #CVE 🔗 https://sh.tc/amazon-bedrock-langsmith-sglang-ai-guvenlik-aciklari

    Post summary

    The tweet discloses critical CVE-2026-3059/3060 affecting Amazon Bedrock, LangSmith, and SGLang, noting potential DNS-based data exfiltration and remote code execution risks with a CVSS score of 9.8; no PoC, exploit tool, patch, or active exploitation evidence is provided.

    0000066
    109 followersView on X
  • SH TC@shtc_social
    Disclosure

    🚨 AI Platformlarında Kritik Güvenlik Açıkları! Amazon Bedrock, LangSmith ve SGLang'de keşfedilen zafiyetler veri sızıntısı ve uzaktan kod çalıştırma riski oluşturuyor. CVE-2026-3059 CVSS 9.8! #SiberGüvenlik #AI #CVE #CyberSecurity 🔗 https://sh.tc/ai-platformlari-kritik-guvenlik-aciklari-bedrock-langsmith-sglang

    Post summary

    The post announces newly discovered CVE-2026-3059 in AI platforms with a high CVSS score, highlighting potential data leakage and remote code execution risks, but provides no PoC, exploit code, or patch information.

    0000067
    109 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3059 SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.load… https://www.cve.org/CVERecord?id=CVE-2026-3059

    Post summary

    CVE-2026-3059 reveals an unauthenticated remote code execution vulnerability in SGLang's multimodal generation module, stemming from unsafe pickle deserialization in the ZMQ broker.

    00000152
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3059 - Critical SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authenti... https://www.thehackerwire.com/vulnerability/CVE-2026-3059/ https://t.co/HsQEWj8V2B

    Post summary

    SGLang’s multimodal generation module is exposed to a critical unauthenticated remote code execution vulnerability caused by deserializing untrusted data with pickle.loads() via its ZMQ broker.

    0000037
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applmsyssglang---

Explore more