CVE-2026-10300
Received Received - Intake
Remote Assertion Failure in SGLang via Inference HTTP Endpoint

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: VulDB

Description
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/lora_manager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lora_path leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-02
AI Q&A
2026-06-02
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in SGLang version 0.5.10.post1, specifically in an unknown function within the file python/sglang/srt/lora/lora_manager.py, part of the Inference HTTP Endpoint component.

The issue arises from manipulation of the argument 'lora_path', which leads to a reachable assertion, meaning the program can be forced into an unexpected state or crash.

The attack exploiting this vulnerability can be launched remotely, but it requires a high level of complexity and is considered difficult to exploit.

A fix has been proposed via a pull request but has not yet been accepted.


How can this vulnerability impact me? :

Exploitation of this vulnerability can cause the affected software to reach an assertion failure, potentially leading to a crash or denial of service.

Since the attack can be launched remotely, it could disrupt the availability of the Inference HTTP Endpoint component.

However, the exploitability is difficult due to the high complexity required to successfully carry out the attack.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart