Security Advisory

CVE-2026-86793

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-11 11:35:20
Last updated 2026-09-14 18:51:51
Assigner certcc
CVSS score 9.8
State PUBLISHED

Description

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.