CVE-2026-7304: Lmsys Sglang
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
Affected products
- Lmsys Sglang: version 0.5.10 only
Published 2026-05-18. Last modified 2026-06-17.