SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
References
| Link | Resource |
|---|---|
| http://vince.cert.org/vuls/id/326070 | Permissions Required |
| https://github.com/sgl-project/sglang/blob/main/python/sglang/srt/elastic_ep/expert_backup_manager.py | Product |
| https://www.kb.cert.org/vuls/id/326070 | Mitigation Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-16 16:19
Updated : 2026-08-10 14:13
NVD link : CVE-2026-14890
Mitre link : CVE-2026-14890
CVE.ORG link : CVE-2026-14890
JSON object : View
Products Affected
lmsys
- sglang
CWE
CWE-502
Deserialization of Untrusted Data
