Impact
SGLang incorporates a ZeroMQ message decoder that unconditionally deserializes PickleWrapper payloads by calling pickle.loads in the function _maybe_unwrap_pickle without any type allowlisting or authentication checks. This flaw allows an attacker who can deliver arbitrary pickle data to the decoder to execute arbitrary Python code during deserialization, leading to full process compromise. The vulnerability is not mitigated by disabling the SGLANG_USE_PICKLE_IPC flag—deserialization still occurs along the msgpack path. If data‑parallel attention is enabled in a distributed configuration with a non‑loopback --dist-init-addr setting, the attacker can influence IPC messages from a remote host, making the attack remotely exploitable.
Affected Systems
All installations of the SGLang project that provide inter‑process communication via ZMQ, especially those that enable the data‑parallel attention feature. The impact applies regardless of the specific version, as the code path exists in the current code base and no version‑specific mitigations are documented.
Risk and Exploitability
The vulnerability permits arbitrary code execution with a high impact on confidentiality, integrity, and availability of the affected system. It is remote‑attainable when the application is configured to listen on a non‑loopback address with data‑parallel attention enabled. No EPSS score is available and the vulnerability is not listed in KEV, but the severity can be inferred from the type of flaw (CWE-502). In the absence of a patch, the risk is significant for systems exposed to external networks.
OpenCVE Enrichment