CVE-2026-7301Disclosure(lmsys / sglang)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lmsys sglang systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sglang

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-18); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
sglang

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-18: 3Mentions · 2026-05-21: 1Mentions · 2026-07-16: 1PoC Mentioned / Linked · 2026-07-16: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-07-16: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-21: 1Technical Details · 2026-07-16: 105-1805-2107-16
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-183
Disclosure2General1
2026-05-211
Disclosure1
2026-07-161
Disclosure1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    CERT/CC warns of unpatched critical flaws in SGLang (CVE-2026-7301) exposing AI inference models to unauthenticated RCE. Restrict your ports now! #SGLang #AISecurity #DeepSeek #ZeroDay #RCE #VulnerabilityAlert #CVE20267301 #MachineLearning https://securityonline.info/sglang-ai-inference-framework-rce-vulnerabilities-cve-2026-7301/ https://t.co/9GvfdEaqxd

    Post summary

    CERT/CC warns of an unpatched, critical remote code execution flaw (CVE-2026-7301) in SGLang that could affect AI inference models, advising users to restrict ports but providing no specific patches or PoC details.

    11020298
    12.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple SGLang Vulnerabilities (CVE-2026-7301, CVE-2026-7302, CVE-2026-7304) Multiple critical flaws in SGLang may allow unauthenticated attackers to achieve remote code execution or arbitrary file writes through insecure deserialization, exposed ROUTER sockets, and path traversal in upload handling. Successful exploitation could lead to full server compromise in exposed AI inference deployments. 👉 Administrators should monitor vendor advisories and apply mitigations or patches as updates become available.

    Post summary

    The tweet announces multiple critical SGLang vulnerabilities that could enable unauthenticated remote code execution or arbitrary file writes, and urges administrators to watch vendor advisories and apply patches when they are released.

    00020127
    255 followersView on X
  • OJOBIT@0J0BIT
    Disclosure

    msgpack can't ship fast enough > a pickle deserialization vulnerability in SGLang's expert-parallel subsystem (CVE-2026-14890) allows unauthenticated RCE; default config enables it and no patch exists > CVE-2026-14890 has no patch; SGLANGUSEPICKLE_IPC defaults to true > CVE-2026-14890 drops that in a single pickle payload > CERT/CC coordinator Christopher Cullen notes the flaw is structurally similar to CVE-2026-7301 and CVE-2026-7304, which hit the multimodal scheduler and custom logit > the project maintainers have started refactoring to msgpack, but no patch for CVE-2026-14890 exists > three moves: (1) set SGLANGUSEPICKLE_IPC to false in your environment, (2) segment the network so the SGLang host is unreachable from untrusted subnets, and (3) https://news.ojobit.com/story/sglang-pickle-deserialization-rce-28a226

    Post summary

    The post discloses an unauthenticated RCE via pickle deserialization in SGLang, with no patch available, and advises disabling pickle IPC and isolating the host as mitigations.

    0000041
    8 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7301 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7301 #CVE-2026-7301 #CVE   #CyberSecurity #InfoSec https://t.co/Y7L2AFGIJG

    Post summary

    The tweet announces the existence of CVE-2026-7301 but provides no further technical details, exploits, patches, or evidence of active exploitation.

    0000054
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7301 Remote Code Execution in SGLang Multimodal Runtime Schedul... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7301 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    CVE-2026-7301 is disclosed as a Remote Code Execution vulnerability in the SGLang Multimodal Runtime Scheduler, with a link to additional details but no PoC, exploit, or patch information.

    0000079
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applmsyssglang0.5.10--

Explore more