Skip to content
Critical RCE Vulnerability in SGLang LLM Framework Disclosed

Critical RCE Vulnerability in SGLang LLM Framework Disclosed

First seen 9 Oct 2026, 10:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 10:34 UTC
  • •CVE-2026-93034 is a critical RCE vulnerability with a CVSS score of 9.8.
  • •The flaw allows unauthenticated remote code execution via deserialization in SGLang's ZMQ message decoder.
  • •No fix is currently available, and operators are advised to restrict network exposure.

SGLang has a critical remote code execution vulnerability, tracked as CVE-2026-93034, due to its ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() without type allowlisting or authentication. This vulnerability persists even when the SGLANG_USE_PICKLE_IPC flag is disabled and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting. The flaw has a CVSS score of 9.8 and affects a widely used high-performance serving framework with 36.9k GitHub stars. The vulnerability was reported to CERT/CC on July 14, 2026, confirmed on September 17, 2026, and publicly disclosed on October 8, 2026. There is currently no fix available, and operators are advised to avoid exposing ZMQ sockets to untrusted networks. This incident follows the recent disclosure of a similar vulnerability in LMCache, indicating a systemic risk in LLM serving frameworks reliant on pickle for performance.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-12
CVE-2026-3060 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-12
CVE-2026-3989 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-12
CVE-2026-3059 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
Vulnerability reported to CERT/CC
CVE-2026-93034 was reported to CERT/CC, marking the start of the vulnerability's disclosure process.
Tech.Yahoo
2026-09-17
Vulnerability confirmed
The vulnerability was confirmed by researchers, indicating its validity and severity.
Tech.Yahoo
2026-10-07
CVE-2026-105192 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-08
Public disclosure of CVE-2026-93034
The vulnerability was publicly disclosed, prompting urgent attention from the cybersecurity community.
Tenable

More articles in this cluster (3)

Following this threat?

Track CVE-2026-105192 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-93034?
CVE-2026-93034 is a critical remote code execution vulnerability in SGLang due to unsafe deserialization.
Are there any patches available?
No, there are currently no patches available for CVE-2026-93034.
What should I do to mitigate this risk?
Avoid exposing ZMQ data-parallel attention sockets to untrusted networks and ensure the --dist-init-addr is bound to loopback.