← All vendors

lmsys

9 known vulnerabilities affecting lmsys products.

Products

sglang 9

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-15969 Medium 1.0% 9.8 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via by…
CVE-2026-14890 Medium 1.0% 9.1 SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socke…
CVE-2026-15971 Medium 0.7% 9.8 SGLang contains an RCE vulnerability when the optional dumper subsystem is enabl…
CVE-2026-15976 Medium 0.6% 9.8 SGLang contains a RCE vulnerability when attempting to load model weights from a…
CVE-2026-15978 Medium 0.5% 7.5 SGLang contains a model weight exfiltration vulnerability when no API keys are c…
CVE-2026-3989 Medium 0.4% 7.8 SGLangs `replay_request_dump.py` contains an insecure pickle.load() without vali…
CVE-2026-15977 Medium 0.4% 7.5 SGLang contains a credential leakage vulnerability in the /server_info endpoint,…
CVE-2026-15974 Low 0.4% 6.5 SGLang contains an SSRF and local file read in the multimodal generation endpoin…
CVE-2026-10775 Low 0.1% 3.6 A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by t…