漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CVE-2026-14890
Vulnerability Description
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
sgl-project sglang 反序列化注入漏洞
Vulnerability Description
sgl-project sglang是sgl-project组织开源的一个用于加速大模型推理的编程语言与运行时系统。 sgl-project sglang 0.5.14及之前版本存在反序列化注入漏洞,该漏洞源于专家并行备份子系统在可路由网络接口上暴露了一个缺乏身份验证和反序列化保护的ZeroMQ PULL套接字,允许攻击者在功能启用且服务可达时提供恶意pickle文件,导致未经验证的远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A