CVE-2026-3059 is a critical unauthenticated remote code execution vulnerability impacting SGLang's multimodal generation module. The flaw stems from the ZMQ broker's use of pickle.loads() to deserialize untrusted data without authentication, allowing an attacker to execute arbitrary code. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a low-complexity network attack vector that can lead to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, CERT/CC has issued an advisory (VU#665416) regarding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.5.5, <= 0.5.9CPE matchmatch criteria | cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.