
🚨Critical - SGLang ZMQ PickleWrapper Deserialization RCE (CVE-2026-93034) SGLang’s ZMQ message decoder deserializes PickleWrapper payloads via pickle.loads() without auth/allowlisting; the gadget path persists via msgpack even when SGLANG_USE_PICKLE_IPC is disabled. With data-parallel attention enabled and --dist-init-addr set to a non-loopback address, remote peers can trigger arbitrary code execution. 👉Affected: SGLang (all versions with ZMQ IPC / dist attention enabled)

