← Vulnerability feed

Vulnerability record · CVE-2026-3989 · published 12 March 2026

CVE-2026-3989: Lmsys sglang deserialization of untrusted data vulnerability

Lmsys · Sglang

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

7.8 CVSS 3.1 High EPSS 0.43% · top 65.3% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3989 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-15969Lmsys sglang deserialization of untrusted data vulnerabilitySGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…EPSS 1.0%9.8CVE-2026-15971Lmsys sglang vulnerabilitySGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena…EPSS 0.73%9.8CVE-2026-15976Lmsys sglang deserialization of untrusted data vulnerabilitySGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…EPSS 0.60%9.8CVE-2026-7301Lmsys sglang deserialization of untrusted data vulnerabilitySGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming…EPSS 0.60%9.8CVE-2026-7304Lmsys sglang deserialization of untrusted data vulnerabilitySGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl…EPSS 0.88%9.8CVE-2026-5760Lmsys sglang code injection vulnerabilitySGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load…EPSS 1.1%9.8CVE-2026-3059Lmsys sglang deserialization of untrusted data vulnerabilitySGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat…EPSS 1.3%9.8CVE-2026-3060Lmsys sglang deserialization of untrusted data vulnerabilitySGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-3989), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.