VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem
A pickle deserialization vulnerability (CVE-2026-14890) exists in the SGLang open-source framework's expert-parallel backup subsystem. This vulnerability allows unauthenticated remote code execution if the subsystem is enabled and reachable over the network. The issue arises because a ZeroMQ PULL socket binds to an external IP without authentication or deserialization safeguards, allowing malicious pickle payloads to be processed. No patch is currently available, and the maintainers have not responded to coordination efforts. Mitigations include disabling the pickle IPC feature and restricting network access to the vulnerable interface.
AI Analysis
Technical Summary
SGLang, a framework for serving large language models, contains a remote code execution vulnerability due to unsafe deserialization of pickle data in its expert-parallel backup subsystem. The subsystem exposes a ZeroMQ PULL socket on a routable network interface without authentication, allowing any network-accessible attacker to send malicious pickle payloads that get deserialized, leading to unauthenticated remote code execution. This vulnerability is tracked as CVE-2026-14890 and is similar in nature to CVE-2026-7301 and CVE-2026-7304 but affects a different subsystem. The vulnerability requires that the expert-parallel backup subsystem be enabled and accessible over the network. No official patch is available, and the maintainers are working on refactoring the codebase to use msgpack instead of pickle for safer deserialization. Until a patch is released, users should disable the pickle IPC feature and restrict network access to the service.
Potential Impact
An unauthenticated attacker with network access to the expert-parallel backup subsystem of SGLang can achieve remote code execution on the host running the vulnerable service. Deployments exposing this interface to untrusted networks are at high risk. This could lead to full compromise of the affected system.
Mitigation Recommendations
No official patch or fix is currently available. Users should immediately restrict network access to the expert-parallel backup subsystem to trusted networks only and implement network segmentation and access controls to prevent unauthorized access. Additionally, users should set the environment variable SGLANG_USE_PICKLE_IPC to "false" in environ.py to disable the vulnerable pickle deserialization feature. Monitor the SGLang project for updates as maintainers are working to replace pickle with safer serialization methods such as msgpack.
VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem
Description
A pickle deserialization vulnerability (CVE-2026-14890) exists in the SGLang open-source framework's expert-parallel backup subsystem. This vulnerability allows unauthenticated remote code execution if the subsystem is enabled and reachable over the network. The issue arises because a ZeroMQ PULL socket binds to an external IP without authentication or deserialization safeguards, allowing malicious pickle payloads to be processed. No patch is currently available, and the maintainers have not responded to coordination efforts. Mitigations include disabling the pickle IPC feature and restricting network access to the vulnerable interface.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SGLang, a framework for serving large language models, contains a remote code execution vulnerability due to unsafe deserialization of pickle data in its expert-parallel backup subsystem. The subsystem exposes a ZeroMQ PULL socket on a routable network interface without authentication, allowing any network-accessible attacker to send malicious pickle payloads that get deserialized, leading to unauthenticated remote code execution. This vulnerability is tracked as CVE-2026-14890 and is similar in nature to CVE-2026-7301 and CVE-2026-7304 but affects a different subsystem. The vulnerability requires that the expert-parallel backup subsystem be enabled and accessible over the network. No official patch is available, and the maintainers are working on refactoring the codebase to use msgpack instead of pickle for safer deserialization. Until a patch is released, users should disable the pickle IPC feature and restrict network access to the service.
Potential Impact
An unauthenticated attacker with network access to the expert-parallel backup subsystem of SGLang can achieve remote code execution on the host running the vulnerable service. Deployments exposing this interface to untrusted networks are at high risk. This could lead to full compromise of the affected system.
Mitigation Recommendations
No official patch or fix is currently available. Users should immediately restrict network access to the expert-parallel backup subsystem to trusted networks only and implement network segmentation and access controls to prevent unauthorized access. Additionally, users should set the environment variable SGLANG_USE_PICKLE_IPC to "false" in environ.py to disable the vulnerable pickle deserialization feature. Monitor the SGLang project for updates as maintainers are working to replace pickle with safer serialization methods such as msgpack.
Technical Details
- Classification
- {"confidence":0.85,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/326070","fetched":true,"fetchedAt":"2026-08-04T13:00:04.879Z","wordCount":612}
Threat ID: 6a71e257bf8831d539d40ecc
Added to database: 08/04/2026, 13:00:07 UTC
Last enriched: 08/04/2026, 13:01:30 UTC
Last updated: 08/04/2026, 13:21:02 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.