Back Tech.Yahoo SGLang LLM Serving Framework Has CVSS 9.8 Pickle Deserialization RCE That Persists ...
In SGLang, the SGLANG_USE_PICKLE_IPC flag fails to secure the framework because the underlying msgpack path continues to process PickleWrapper types. Research by m00dy.sh confirms that this oversight allows for unauthenticated remote code execution (RCE). The vulnerability, tracked as CVE-2026-93034 , persists despite attempts to disable pickle-based inter-process communication.
SGLang is a high-performance serving framework with 36.9k GitHub stars, widely used across AI labs and enterprise environments for large-scale inference and agentic workloads. The flaw resides in the ZMQ message decoder, which performs unconditional deserialization via pickle.loads() within the _maybe_unwrap_pickle function. This operation proceeds without any type allowlisting or authentication. The severity is underscored by a CVSS v3 score of 9.8 and a CVSS v2 score of 10.0. The vulnerability becomes remotely exploitable when data-parallel attention is enabled with a non-loopback –dist-init-addr configuration.
This incident is the second instance of a pickle deserialization RCE affecting LLM inference infrastructure within a single week. It follows the disclosure of LMCache CVE-2026-105192 ( Forkast Post 131502 , FEATURED), which utilized an identical ZeroMQ plus pickle pattern for its distributed KV cache. The appearance of this vulnerability class across independent frameworks within days indicates a structural issue rather than an isolated bug. It suggests that the reliance on pickle for inter-process communication to achieve performance gains is deeply embedded in the current generation of LLM serving stacks.
The root cause is a pervasive design philosophy of trust-through-defaults. These frameworks operate under the assumption that the inference cluster network is inherently trusted. Developers prioritize low-latency IPC, and pickle is often the default choice for serializing complex objects. However, this assumption of a secure, isolated network environment fails the moment the infrastructure becomes reachable, whether through misconfiguration or network exposure. The recurrence of this pattern indicates that the industry's reliance on pickle for performance is creating a systemic risk across the AI infrastructure ecosystem.
For operators, the situation is currently difficult. There is no fix available for CVE-2026-93034, and no security advisory has been published by the sgl-project/sglang repository. The vulnerability was reported to CERT/CC (VU#765030) on July 14, 2026, and confirmed on September 17, 2026, before public disclosure on October 7, 2026. While the issue was confirmed in SGLang v0.5.18 and appears to persist in v0.5.20, there is no official patch. Until upstream developers address the _maybe_unwrap_pickle function, the only viable mitigations are operational: do not expose ZMQ data-parallel attention sockets to untrusted networks, ensure –dist-init-addr is bound strictly to loopback, and avoid the msgpack path entirely.
SGLang has faced this specific security challenge before. In March 2026, the framework was subject to CVE-2026-3059, CVE-2026-3060, and CVE-2026-3989, which were disclosed by Igor Stepansky at Orca Security and subsequently patched in v0.5.10. The fact that the same vulnerability class has returned despite these prior efforts highlights the difficulty of removing dangerous deserialization patterns once they are integrated into the core architecture of a framework. As LLM serving infrastructure continues to scale, the tension between performance-driven design and secure-by-default architecture remains a critical point of failure for enterprise AI deployments.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
