Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
CVE-2026-86793
SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.
References
Affected products
SGLang
- =<0.5.18