PT-2026-66559 · Sglang · Sglang

CVE-2026-15971

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SGLang (affected versions not specified)
Description An issue exists when the optional dumper subsystem is enabled and the DUMPER SERVER PORT variable is set. This allows for a sandbox escape, which can lead to remote code execution during inference requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Disable the optional dumper subsystem or avoid setting the DUMPER SERVER PORT variable to mitigate the risk.

Exploit

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15971
GHSA-H6RF-77VV-9MVJ

Affected Products

Sglang