Beveiligingsadvies

CVE-2026-15969

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-30 18:09:21
Laatst bijgewerkt 2026-07-31 17:37:45
Toegewezen door certcc
CVSS-score 9.8
Status PUBLISHED

Beschrijving

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.