CVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
Configurations

No configuration.

History

16 Jul 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-502

16 Jul 2026, 17:16

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/326070 -

16 Jul 2026, 16:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 16:19

Updated : 2026-07-16 19:16


NVD link : CVE-2026-14890

Mitre link : CVE-2026-14890

CVE.ORG link : CVE-2026-14890


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data