CVE-2026-3059

CRITICAL9.8EPSS 1.9%

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker

Published: 3/12/2026Modified: 4/7/2026

Description

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (7)