Back to CVE List

CVE-2026-15976

Vulnerability Description

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
SGLang
Product
SGLang

External References

Discussion (0)

Add Comment

No comments yet. Be the first!