CVE-2026-93034: Sglang

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.

Affected products

  • Sglang Sglang: up to and including v0.5.20

Published 2026-10-08. Last modified 2026-10-08.