lmsys kayıtları
lmsys üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data8
- CWE-35 Path Traversal: '.../...//'1
- CWE-404 Improper Resource Shutdown or Release1
- CWE-522 Insufficiently Protected Credentials1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-3059İstismar yok | SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrlmsys · sglang · CWE-502 | Kritik9,8 | — | %1,3 | 12 Mar 2026 |
39İzleyin | CVE-2026-3060İstismar yok | SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, whilmsys · sglang · CWE-502 | Kritik9,8 | — | %1,3 | 12 Mar 2026 |
39İzleyin | CVE-2026-5760Kavram kanıtı | SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_templatlmsys · sglang · CWE-94 | Kritik9,8 | — | %1,1 | 20 Nis 2026 |
39İzleyin | CVE-2026-15969İstismar yok | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrlmsys · sglang · CWE-502 | Kritik9,8 | — | %1,0 | 30 Tem 2026 |
39İzleyin | CVE-2026-7304İstismar yok | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor optionlmsys · sglang · CWE-502 | Kritik9,8 | — | %0,9 | 18 May 2026 |
39İzleyin | CVE-2026-15971İstismar yok | SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT islmsys · sglang · CWE-95 | Kritik9,8 | — | %0,7 | 30 Tem 2026 |
39İzleyin | CVE-2026-15976İstismar yok | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weilmsys · sglang · CWE-502 | Kritik9,8 | — | %0,6 | 30 Tem 2026 |
39İzleyin | CVE-2026-7301İstismar yok | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() onlmsys · sglang · CWE-502 | Kritik9,8 | — | %0,6 | 18 May 2026 |
36İzleyin | CVE-2026-14890İstismar yok | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authlmsys · sglang · CWE-502 | Kritik9,1 | — | %1,0 | 16 Tem 2026 |
36İzleyin | CVE-2026-7302İstismar yok | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrlmsys · sglang · CWE-35 | Kritik9,1 | — | %0,6 | 18 May 2026 |
31İzleyin | CVE-2026-3989İstismar yok | SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization.lmsys · sglang · CWE-502 | Yüksek7,8 | — | %0,4 | 12 Mar 2026 |
30İzleyin | CVE-2026-15978İstismar yok | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a lmsys · sglang · CWE-306 | Yüksek7,5 | — | %0,5 | 30 Tem 2026 |
30İzleyin | CVE-2026-15977İstismar yok | SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information whenlmsys · sglang · CWE-522 | Yüksek7,5 | — | %0,4 | 30 Tem 2026 |
26İzleyin | CVE-2026-15974İstismar yok | SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowinlmsys · sglang · CWE-918 | Orta6,5 | — | %0,4 | 30 Tem 2026 |
4İzleyin | CVE-2026-10775İstismar yok | sgl-project SGLang Cache data_hash denial of servicelmsys · sglang · CWE-404 | Düşük1,1 | — | %0,1 | 3 Haz 2026 |
- CVE-2026-305939İzleyin
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untr
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang12 Mar 2026
- CVE-2026-306039İzleyin
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, whi
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang12 Mar 2026
- CVE-2026-576039İzleyin
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_templat
KritikCVSS 9,8Kavram kanıtıEPSS %1lmsys · sglang20 Nis 2026
- CVE-2026-1596939İzleyin
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitr
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang30 Tem 2026
- CVE-2026-730439İzleyin
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang18 May 2026
- CVE-2026-1597139İzleyin
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang30 Tem 2026
- CVE-2026-1597639İzleyin
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_wei
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang30 Tem 2026
- CVE-2026-730139İzleyin
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on
KritikCVSS 9,8İstismar yokEPSS %1lmsys · sglang18 May 2026
- CVE-2026-1489036İzleyin
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain auth
KritikCVSS 9,1İstismar yokEPSS %1lmsys · sglang16 Tem 2026
- CVE-2026-730236İzleyin
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitr
KritikCVSS 9,1İstismar yokEPSS %1lmsys · sglang18 May 2026
- CVE-2026-398931İzleyin
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization.
YüksekCVSS 7,8İstismar yokEPSS %0lmsys · sglang12 Mar 2026
- CVE-2026-1597830İzleyin
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a
YüksekCVSS 7,5İstismar yokEPSS %1lmsys · sglang30 Tem 2026
- CVE-2026-1597730İzleyin
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when
YüksekCVSS 7,5İstismar yokEPSS %0lmsys · sglang30 Tem 2026
- CVE-2026-1597426İzleyin
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowin
OrtaCVSS 6,5İstismar yokEPSS %0lmsys · sglang30 Tem 2026
- CVE-2026-107754İzleyin
sgl-project SGLang Cache data_hash denial of service
DüşükCVSS 1,1İstismar yokEPSS %0lmsys · sglang3 Haz 2026