Impact
SGLang implements an HTTP endpoint at /update_weights_from_tensor that performs Python pickle deserialization without requiring any authentication if no secret keys are configured. The library's SafeUnpickler policy can be subverted because builtins.import and builtins.getattr can be accessed, allowing an attacker to craft a pickle payload that triggers the REDUCE function and creates arbitrary code execution on the host running the SGLang process. This vulnerability results in full remote code execution on the machine and is a classic example of insecure deserialization. The CVSS score is 9.8, indicating a critical level of severity.
Affected Systems
The flaw affects all deployments of the SGLang product where the /update_weights_from_tensor endpoint is available and authentication keys have not been set. No specific product version numbers are enumerated in the data, so any instance that runs the vulnerable code path is considered at risk.
Risk and Exploitability
The absence of authentication means an attacker only needs the ability to send an HTTP request to the target host. The CVSS score is 9.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, yet the combination of unauthenticated access and arbitrary code execution signifies a severe risk. The likely attack vector is a malicious HTTP request; if the endpoint is reachable from the Internet or an untrusted network, exploitation is straightforward and would grant the attacker the same privileges as the SGLang process.
OpenCVE Enrichment