9.8
CVE-2026-15971
- EPSS 0.4%
- Veröffentlicht 30.07.2026 18:07:24
- Zuletzt bearbeitet 04.08.2026 20:42:42
- CVE-Watchlists
- Unerledigt
CVE-2026-15971
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.332 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://thoughts.apoorvdayal.com/posts/sglang-disclosures/
https://github.com/sgl-project/sglang/security/advisories/GHSA-h6rf-77vv-9mvj