#SGLang
All CosmicBytez Labs articles tagged #SGLang, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-14890: SGLang ZeroMQ Unauthenticated RCE via Pickle Deserialization
A critical unauthenticated remote code execution vulnerability in the SGLang AI inference framework allows attackers to deliver malicious pickle payloads...
- Security
CVE-2026-7301: SGLang ROUTER Socket Exposes Unsafe
A critical CVSS 9.8 vulnerability in SGLang's multimodal AI runtime scheduler binds its ROUTER socket to 0.0.0.0 by default and passes incoming messages...
- Security
CVE-2026-7302: SGLang Unauthenticated Path Traversal
A critical CVSS 9.1 path traversal vulnerability in SGLang's multimodal AI runtime allows unauthenticated attackers to write arbitrary files anywhere the...
- News
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious
A critical CVSS 9.8 command injection vulnerability in the SGLang AI inference framework allows attackers to achieve remote code execution by supplying a...
- News
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable
Security researchers disclosed critical flaws across three major AI platforms: Amazon Bedrock AgentCore's sandbox can be bypassed via DNS to exfiltrate...