Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-93034: sglang may run attacker code via remote messages
CVE-2026-93034 · published 1 day ago
Summary
The sglang software can execute any code an attacker sends if it receives specially crafted messages, especially when data-parallel mode is turned on with a network address other than localhost. This means a malicious user could take control of the system running sglang. Disable remote data‑parallel connections or restrict message handling until the issue is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| sglang | sglang | <= v0.5.20 |
Original advisory text
CVE-2026-93034
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published8 Oct 2026
Updated9 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta