Junglewise Threat Intelligence

CVE-2026-7304: SGLang RCE via unsafe deserialization in custom logit processor

CVE-2026-7304 · Severity: critical · CVSS 9.8 · Published 2026-05-18

Technologies: SGLang Project SGLang, sglang (PyPI). Vendors: SGLang Project, PyPI.

Executive brief

SGLang is an open-source framework used to serve large language models (LLMs) and AI models. A critical security flaw exists when the custom logit processor feature is enabled, allowing an unauthenticated attacker to execute arbitrary commands on the server. This could lead to a complete system takeover, theft of sensitive AI models or data, and disruption of AI services.

Technical details

A deserialization vulnerability (CWE-502) exists in SGLang's custom logit processor component. When the '--enable-custom-logit-processor' flag is set, the generation endpoint accepts a 'custom_logit_processor' field containing a hex-encoded 'dill' payload. The server invokes 'dill.loads()' on this untrusted input without validation, allowing a remote, unauthenticated attacker to achieve arbitrary code execution. This affects versions 0.4.1.post7 through 0.5.12; as of the advisory date, no official patch is available, and users are advised to disable the vulnerable flag and restrict network access.

Affected products

  • SGLang Project sglang >= 0.4.1.post7, <= 0.5.12

Timeline

  • 2026-03-10: disclosed: Vulnerability reported to maintainers by Antiproof.
  • 2026-05-15: advisory: CERT/CC published Vulnerability Note VU#777338.
  • 2026-05-18: disclosed: GitHub Advisory and NVD entry published.

References

Related threats