
CVE-2026-3989 SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a… https://www.cve.org/CVERecord?id=CVE-2026-3989
Post summary
The post notes insecure deserialization via pickle.load() in SGLangs’ replay_request_dump.py, but provides no PoC, exploit, or patch information.
