CVE-2026-14890

🟠 Łataj w tym tygodniu

Brak uwierzytelnienia w SGLang umożliwia zdalne wykonanie kodu przez złośliwy plik pickle.

CVSS
9.1
EPSS
0.9%
Exploit
none
Vendor
lmsys
Opis źródłowy (NVD)

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.

deserialization rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.9%
Opublikowano (NVD)2026-07-16 16:19:00 UTC
Ostatnia modyfikacja (NVD)2026-08-10 14:13:13 UTC
Referencje