Tech.Yahoo Critical RCE Vulnerability in SGLang LLM Framework Disclosed
Article Content
- •CVE-2026-93034 is a critical RCE vulnerability with a CVSS score of 9.8.
- •The flaw allows unauthenticated remote code execution via deserialization in SGLang's ZMQ message decoder.
- •No fix is currently available, and operators are advised to restrict network exposure.
SGLang has a critical remote code execution vulnerability, tracked as CVE-2026-93034, due to its ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() without type allowlisting or authentication. This vulnerability persists even when the SGLANG_USE_PICKLE_IPC flag is disabled and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting. The flaw has a CVSS score of 9.8 and affects a widely used high-performance serving framework with 36.9k GitHub stars. The vulnerability was reported to CERT/CC on July 14, 2026, confirmed on September 17, 2026, and publicly disclosed on October 8, 2026. There is currently no fix available, and operators are advised to avoid exposing ZMQ sockets to untrusted networks. This incident follows the recent disclosure of a similar vulnerability in LMCache, indicating a systemic risk in LLM serving frameworks reliant on pickle for performance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-105192 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2026-93034?
Are there any patches available?
What should I do to mitigate this risk?
Continue Reading
Critical LMCache Vulnerability Allows Unauthenticated Remote Code Execution A critical vulnerability (CVE-2026-105192) in LMCache, an open-source key-value cache for large language models, allows unauthenticated remote code execution. The flaw, rated CVSS 9.8, affects versions 0.3.9 to 0.5.5 and is triggered by sending a crafted message to an unauthenticated ZeroMQ socket on port 5555. This…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…