CVE-2026-7301: Lmsys Sglang
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
Affected products
- Lmsys Sglang: version 0.5.10 only
Published 2026-05-18. Last modified 2026-06-17.