HIGH
CVE-2026-3989
Published Mar 12, 2026
7.8
HIGHCVSS 3.1
EPSS 0.43%
Description
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.
Affected products
-
Affected
- 0.5.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11561 Advisory
- https://github.com/advisories/GHSA-hvwj-8w5g-28rg Advisory
- https://github.com/sgl-project/sglang/blob/main/scripts/playground/replay_request_dump.py Product
- https://github.com/sgl-project/sglang/pull/20904 Issue TrackingPatch
- https://github.com/sgl-project/sglang/releases/tag/v0.5.10 Release Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-3989
- https://orca.security/resources/blog/sglang-llm-framework-rce-vulnerabilities ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11561 | Advisory | |
| https://github.com/advisories/GHSA-hvwj-8w5g-28rg | Advisory | |
| https://github.com/sgl-project/sglang/blob/main/scripts/playground/replay_request_dump.py | Product | |
| https://github.com/sgl-project/sglang/pull/20904 | Issue TrackingPatch | |
| https://github.com/sgl-project/sglang/releases/tag/v0.5.10 | Release Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-3989 | ||
| https://orca.security/resources/blog/sglang-llm-framework-rce-vulnerabilities | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Mar 12, 2026
Updated Apr 7, 2026
Reserved Mar 11, 2026
Link CVE-2026-3989
CISA Vulnrichment
Updated Mar 16, 2026
Red Hat
No data
GitHub
Link GHSA-HVWJ-8W5G-28RG