CVE-2026-3060 is a critical unauthenticated remote code execution vulnerability affecting the lmsys sglang product, specifically within its encoder parallel disaggregation system. This flaw arises from the unsafe deserialization of untrusted data using pickle.loads() without authentication. Rated with a CVSS score of 9.8 (CRITICAL), it can be exploited remotely with low attack complexity, requiring no privileges or user interaction, leading to a complete compromise of confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog and lacking public exploit code, CERT/CC has published an advisory, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.5.5, <= 0.5.9CPE matchmatch criteria | cpe:2.3:a:lmsys:sglang:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.