Description
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

SGLang incorporates a ZeroMQ message decoder that unconditionally deserializes PickleWrapper payloads by calling pickle.loads in the function _maybe_unwrap_pickle without any type allowlisting or authentication checks. This flaw allows an attacker who can deliver arbitrary pickle data to the decoder to execute arbitrary Python code during deserialization, leading to full process compromise. The vulnerability is not mitigated by disabling the SGLANG_USE_PICKLE_IPC flag—deserialization still occurs along the msgpack path. If data‑parallel attention is enabled in a distributed configuration with a non‑loopback --dist-init-addr setting, the attacker can influence IPC messages from a remote host, making the attack remotely exploitable.

Affected Systems

All installations of the SGLang project that provide inter‑process communication via ZMQ, especially those that enable the data‑parallel attention feature. The impact applies regardless of the specific version, as the code path exists in the current code base and no version‑specific mitigations are documented.

Risk and Exploitability

The vulnerability permits arbitrary code execution with a high impact on confidentiality, integrity, and availability of the affected system. It is remote‑attainable when the application is configured to listen on a non‑loopback address with data‑parallel attention enabled. No EPSS score is available and the vulnerability is not listed in KEV, but the severity can be inferred from the type of flaw (CWE-502). In the absence of a patch, the risk is significant for systems exposed to external networks.

Generated by OpenCVE AI on October 8, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest SGLang release that secures the _maybe_unwrap_pickle function or implements a whitelist for deserialization.
  • Configure SGLANG_USE_PICKLE_IPC to false and restrict all ZMQ IPC connections to the loopback interface, preventing remote delivery of pickle payloads.
  • Disable data‑parallel attention for any SGLang deployment that is reachable from external hosts; run the model in single‑process mode when remote access is required.

Generated by OpenCVE AI on October 8, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.
Title CVE-2026-93034
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-10-08T14:00:09.084Z

Reserved: 2026-09-17T15:20:20.432Z

Link: CVE-2026-93034

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:57.117

Modified: 2026-10-08T15:17:57.220

Link: CVE-2026-93034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data