CVE-2026-93034
Deferred Deferred - Pending Action

Arbitrary Code Execution in SGLang via Unsafe Pickle Deserialization

Vulnerability report for CVE-2026-93034, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: CERT/CC

Description

SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SGLang SGLang 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-93034 is an arbitrary code execution flaw in SGLang v0.5.18 caused by unsafe deserialization of PickleWrapper payloads via pickle.loads() in the ZMQ message decoder. Even when SGLANG_USE_PICKLE_IPC is disabled, the vulnerability persists through the msgpack path. It becomes remotely exploitable if data-parallel attention is enabled with a non-loopback network binding.

Detection Guidance

Check if SGLang is running with data-parallel attention enabled and bound to a non-loopback TCP address. Inspect logs for ZeroMQ message decoding errors or unexpected PickleWrapper usage. Monitor for arbitrary file creation or process ID markers in service directories.

Impact Analysis

An attacker could send malicious messages to an exposed internal receiver, executing arbitrary code on the affected system. This requires specific non-default settings like data-parallel attention and a non-loopback TCP address. Successful exploitation grants control over the service or underlying machine.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially exposing sensitive data processed by SGLang. For GDPR, it may violate principles of data protection by enabling unauthorized access to personal data. For HIPAA, it could compromise protected health information if exploited in healthcare systems.

Mitigation Strategies

Disable data-parallel attention and ensure internal receivers only bind to loopback addresses. Update SGLang to a patched version if available. Block external access to internal ZeroMQ ports and review message serialization configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93034. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart