top of page
perceptive_background_267k.jpg

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untr…

Published:

11 maart 2026 om 23:00:00

Alert date:

12 maart 2026 om 16:03:23

Source:

nvd.nist.gov

Click to open the original link from this advisory

Emerging Technologies, Web Technologies

SGLang's encoder parallel disaggregation system contains a critical vulnerability that allows unauthenticated remote code execution. The vulnerability exists in the disaggregation module which uses pickle.loads() to deserialize untrusted data without proper authentication. This creates a significant security risk as attackers can potentially execute arbitrary code on affected systems. The vulnerability affects the encoder receiver component of the SGLang framework. The issue has been documented and analyzed by security researchers at Orca Security.

Technical details

Mitigation steps:

Affected products:

SGLang

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page