Junglewise Threat Intelligence

CVE-2026-3989: SGLang unsafe pickle deserialization in replay_request_dump.py

CVE-2026-3989 · Severity: high · CVSS 7.8 · Published 2026-03-12

Technologies: SGLang Project SGLang, sglang (PyPI). Vendors: SGLang Project, PyPI.

Executive brief

SGLang's replay_request_dump.py script is a utility used to replay captured LLM service requests for testing and debugging. The script contains an insecure deserialization vulnerability that allows attackers to execute arbitrary code by providing a malicious pickle file. An attacker who can control input files processed by this script can gain full code execution on the host system.

Technical details

The vulnerability is an unsafe deserialization issue in the replay_request_dump.py script, which uses Python's pickle.load() function without proper validation or restrictions. The pickle protocol is inherently unsafe and can deserialize and execute arbitrary Python code embedded in crafted .pkl files. An attacker can craft a malicious pickle file containing gadget chains (e.g., using os.system, subprocess.Popen, or eval) that execute when deserialized. The attack vector requires local file access or the ability to provide a malicious .pkl file to the script. The fix, merged in March 2026, replaces the unsafe pickle.load() with safe_pickle_load() using a SafeUnpickler that maintains an allowlist/denylist of safe classes and blocks known RCE gadget chains.

Affected products

  • SGLang Project SGLang all versions prior to fix

Timeline

  • 2026-03-12: disclosed: CVE-2026-3989 published
  • 2026-03-27: patched: Security fix merged in PR #20904 replacing unsafe pickle.load with safe_pickle_load

References

Related threats