CVE-2026-7304Disclosure(lmsys / sglang)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lmsys sglang systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sglang

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-05-18); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
sglang

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-18: 3Mentions · 2026-06-03: 1Mentions · 2026-06-09: 1Mentions · 2026-07-16: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-07-16: 1Technical Details · 2026-05-18: 2Technical Details · 2026-06-09: 1Technical Details · 2026-07-16: 105-1806-0306-0907-16
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-183
Disclosure3
2026-06-031
General1
2026-06-091
Disclosure1
2026-07-161
Disclosure1
Full discourse6 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-7304: SGLang – Unauthenticated RCE via dill.loads https://blog.securelayer7.net/cve-2026-7304-sglang-unauthenticated-rce/

    Post summary

    SGLang (CVE‑2026‑7304) is an unauthenticated remote code execution vulnerability triggered by a malicious dill.loads payload, as disclosed in a blog post.

    0601241.8K
    158.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple SGLang Vulnerabilities (CVE-2026-7301, CVE-2026-7302, CVE-2026-7304) Multiple critical flaws in SGLang may allow unauthenticated attackers to achieve remote code execution or arbitrary file writes through insecure deserialization, exposed ROUTER sockets, and path traversal in upload handling. Successful exploitation could lead to full server compromise in exposed AI inference deployments. 👉 Administrators should monitor vendor advisories and apply mitigations or patches as updates become available.

    Post summary

    SGLang has three critical vulnerabilities that enable remote code execution and arbitrary file writes; administrators should monitor advisories and apply forthcoming patches.

    00020127
    255 followersView on X
  • OJOBIT@0J0BIT
    Disclosure

    msgpack can't ship fast enough > a pickle deserialization vulnerability in SGLang's expert-parallel subsystem (CVE-2026-14890) allows unauthenticated RCE; default config enables it and no patch exists > CVE-2026-14890 has no patch; SGLANGUSEPICKLE_IPC defaults to true > CVE-2026-14890 drops that in a single pickle payload > CERT/CC coordinator Christopher Cullen notes the flaw is structurally similar to CVE-2026-7301 and CVE-2026-7304, which hit the multimodal scheduler and custom logit > the project maintainers have started refactoring to msgpack, but no patch for CVE-2026-14890 exists > three moves: (1) set SGLANGUSEPICKLE_IPC to false in your environment, (2) segment the network so the SGLang host is unreachable from untrusted subnets, and (3) https://news.ojobit.com/story/sglang-pickle-deserialization-rce-28a226

    Post summary

    SGLang's pickle deserialization flaw (CVE-2026-14890) enables unauthenticated remote code execution in the default configuration, and no patch exists—mitigation involves disabling the feature and network isolation.

    0000041
    8 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-7304: Lmsys Sglang RCE Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04jVn340

    Post summary

    The provided text only gives a headline and a link, with no substantive details about the vulnerability, exploits, or mitigations.

    0000031
    32 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7304 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7304 #CVE-2026-7304 #CVE   #CyberSecurity #InfoSec https://t.co/e5h3eB0lr2

    Post summary

    A tweet announces the existence of CVE-2026-7304 but offers no technical details, exploitation evidence, or mitigation information.

    0000060
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7304 Unauthenticated Remote Code Execution in SGLang Multimodal Generation Runtime https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7304

    Post summary

    A brief announcement of CVE-2026-7304, describing an unauthenticated RCE in SGLang Multimodal Generation Runtime, with a link to a vulnerability details page but no further exploitation or patch information.

    0000074
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applmsyssglang0.5.10--

Explore more