Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2026-7301
Vulnerability Description
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
sglang 代码问题漏洞
Vulnerability Description
sglang是sgl-project开源的一个用于加速大模型推理的编程语言与运行时系统。 sglang存在代码问题漏洞,该漏洞源于多模态生成运行时调度器的ROUTER套接字默认绑定到0.0.0.0,且包含一个调用pickle.loads()处理传入消息的接收器,可能导致暴露于互联网时实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A