9.8
CVE-2026-15976
- EPSS 0.33%
- Veröffentlicht 30.07.2026 18:07:44
- Zuletzt bearbeitet 04.08.2026 20:41:43
- CVE-Watchlists
- Unerledigt
CVE-2026-15976
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.258 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://thoughts.apoorvdayal.com/posts/sglang-disclosures/
https://github.com/sgl-project/sglang/security/advisories/GHSA-wf98-gv64-5wrf