Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-93088: SGLang runtime can run malicious code remotely

CVE-2026-93088 · published 18 days ago
Summary

The SGLang multimodal generation system accepts network messages on a socket that is open to anyone and processes them with a function that can execute code. An attacker could send specially crafted data and cause the system to run arbitrary code, potentially taking control of the server. Apply the vendor's security update or block external access to the affected socket until a fix is deployed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sglang sglang <= 0.5.14
Original advisory text
CVE-2026-93088
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Sources
CVE-2026-93088 · MITRE
Track software like this
Free during beta