Back

HIGH

CVE-2026-3989

Published Mar 12, 2026

Description

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner certcc
Published Mar 12, 2026
Updated Apr 7, 2026
Reserved Mar 11, 2026

CISA Vulnrichment

Updated Mar 16, 2026

NVD

Status Analyzed
Modified Aug 10, 2026

Red Hat

No data

ENISA EUVD

Assigner certcc
Published Mar 12, 2026
Updated Apr 7, 2026