Critical RCE and Path Traversal Vulnerabilities Found in SGLang Framework
Article Content
- •Three critical vulnerabilities in SGLang allow RCE and path traversal attacks.
- •CVE-2026-7301 and CVE-2026-7304 enable RCE via unsafe deserialization.
- •No patches are available, and affected users should implement mitigations.
Three vulnerabilities have been identified in the SGLang framework, including two remote code execution (RCE) vulnerabilities and one path traversal vulnerability. These flaws allow unauthenticated attackers to execute arbitrary code or write files on affected systems. The vulnerabilities are tracked as CVE-2026-7301, CVE-2026-7302, and CVE-2026-7304, all published on 2026-05-18. Exploitation requires network access to the SGLang service, particularly when the multimodal generation mode is enabled. No patches are currently available, and the maintainers have not responded to disclosure attempts. The vulnerabilities stem from unsafe deserialization and improper handling of file uploads. Deployments exposing the affected interfaces to untrusted networks are at the highest risk. Security professionals are advised to monitor their systems closely until a patch is released.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track OpenAI and CVE-2026-3059 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…