Executive brief
SGLang is a serving framework for large language and multimodal models. An unauthenticated remote attacker who can reach the disaggregated diffusion orchestrator's ZeroMQ ROUTER socket can execute arbitrary code on the server by sending a malicious serialized Python object, leading to complete system compromise.
Technical details
The DiffusionServer head node binds an unauthenticated ZeroMQ ROUTER socket and directly deserializes the final frame of incoming multipart messages using pickle.loads() without authentication or validation. An attacker with network access to the socket can craft a malicious pickle payload that executes arbitrary Python code in the server process context. No patches are currently available.
Affected products
- SGLang SGLang 0.5.14 and earlier
Timeline
- 2026-07-03: disclosed: Reported via GitHub Security Advisory
- 2026-09-17: advisory: CERT/CC verified and assigned CVE-2026-93088
- 2026-09-22: other: Advisory published with supplementary findings