CVE-2026-3059

Description

SGLangs multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.253

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2026-3059,CVE-2026-3060,CVE-2026-3989 are affected in Python-sglang 0.5.9Windows
Vulnerabilities CVE-2026-3059,CVE-2026-3060,CVE-2026-3989 are affected in Python-sglang for linux 0.5.9Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234