İçeriğe atla
Noroxi

lmsys kayıtları

lmsys üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
9
Düzeltme kaydı olan
%20
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2026-3059
    39İzleyin

    SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untr

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang12 Mar 2026

  • CVE-2026-3060
    39İzleyin

    SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, whi

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang12 Mar 2026

  • CVE-2026-5760
    39İzleyin

    SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_templat

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    lmsys · sglang20 Nis 2026

  • CVE-2026-15969
    39İzleyin

    SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitr

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang30 Tem 2026

  • CVE-2026-7304
    39İzleyin

    SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang18 May 2026

  • CVE-2026-15971
    39İzleyin

    SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang30 Tem 2026

  • CVE-2026-15976
    39İzleyin

    SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_wei

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang30 Tem 2026

  • CVE-2026-7301
    39İzleyin

    SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on

    KritikCVSS 9,8İstismar yokEPSS %1

    lmsys · sglang18 May 2026

  • CVE-2026-14890
    36İzleyin

    SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain auth

    KritikCVSS 9,1İstismar yokEPSS %1

    lmsys · sglang16 Tem 2026

  • CVE-2026-7302
    36İzleyin

    SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitr

    KritikCVSS 9,1İstismar yokEPSS %1

    lmsys · sglang18 May 2026

  • CVE-2026-3989
    31İzleyin

    SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization.

    YüksekCVSS 7,8İstismar yokEPSS %0

    lmsys · sglang12 Mar 2026

  • CVE-2026-15978
    30İzleyin

    SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a

    YüksekCVSS 7,5İstismar yokEPSS %1

    lmsys · sglang30 Tem 2026

  • CVE-2026-15977
    30İzleyin

    SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when

    YüksekCVSS 7,5İstismar yokEPSS %0

    lmsys · sglang30 Tem 2026

  • CVE-2026-15974
    26İzleyin

    SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowin

    OrtaCVSS 6,5İstismar yokEPSS %0

    lmsys · sglang30 Tem 2026

  • sgl-project SGLang Cache data_hash denial of service

    DüşükCVSS 1,1İstismar yokEPSS %0

    lmsys · sglang3 Haz 2026