SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sglang
Sglang sglang |
|
| Vendors & Products |
Sglang
Sglang sglang |
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. | |
| Title | CVE-2026-15969 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-07-31T17:37:45.471Z
Reserved: 2026-07-16T15:25:47.694Z
Link: CVE-2026-15969
Updated: 2026-07-31T17:37:31.340Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T19:30:04Z