{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-93034", "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b", "state": "PUBLISHED", "assignerShortName": "certcc", "dateReserved": "2026-09-17T15:20:20.432Z", "datePublished": "2026-10-08T14:00:09.084Z", "dateUpdated": "2026-10-08T14:00:09.084Z" }, "containers": { "cna": { "title": "CVE-2026-93034", "descriptions": [ { "lang": "en", "value": "SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting." } ], "source": { "discovery": "UNKNOWN" }, "affected": [ { "vendor": "SGLang", "product": "SGLang", "versions": [ { "status": "affected", "version": "0", "lessThanOrEqual": "v0.5.20", "versionType": "custom" } ] } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-502 Deserialization of Untrusted Data" } ] } ], "references": [ { "url": "https://github.com/sgl-project/sglang/tree/main" }, { "url": "https://m00dy.sh/notes/disabling-pickle-did-not-remove-pickle?palette=mineral" } ], "x_generator": { "engine": "VINCE 3.0.50", "env": "prod", "origin": "https://cveawg.mitre.org/api/cve/CVE-2026-93034" }, "providerMetadata": { "orgId": "37e5125f-f79b-445b-8fad-9564f167944b", "shortName": "certcc", "dateUpdated": "2026-10-08T14:00:09.084Z" } } } }