SGLang CVE-2026-93034 (CVSS 9.8): internal ZeroMQ messages are still unpickled even with Pickle IPC turned off, giving remote code execution when data-parallel attention binds to a network address; no confirmed fix yet
A researcher writing as m00dy published findings on 7 October 2026, coordinated through CERT/CC (VU#765030), and CVE-2026-93034 was published on 8 October for SGLang, a widely used serving engine for large language models. SGLang's processes pass internal messages over ZeroMQ. By default they use Python Pickle (SGLANG_USE_PICKLE_IPC=true), which can run code while loading data; operators can switch to MessagePack, but the MessagePack path still accepts a PickleWrapper record and immediately unpickles it without a type allowlist or authentication. On a stock v0.5.18 service running a real model across two GPUs, an unauthenticated peer on a second machine got its code to run inside the detokenizer process, with the setting both on and off. In the default single-node layout the receiver is local to the host; it becomes reachable over the network when data-parallel attention is enabled with a non-loopback --dist-init-addr. Source inspection found the same code in v0.5.20 and main on 1 October; the researcher had not assessed v0.5.21 (released 2 October), so no fixed version is confirmed. CVSS 3.1 9.8 (CERT/CC). No exploitation reported. Primary: researcher write-up and CVE record.
- Product
- SGLang LLM serving engine — ZeroMQ inter-process message decoding (detokenizer and other receivers)
- Versions
- v0.5.18 confirmed; same code seen in v0.5.20 and main on 1 Oct 2026; v0.5.21 not assessed
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- No fixed release confirmed. Keep SGLang's internal ZeroMQ ports on loopback or a private, firewalled cluster network; if you use data-parallel attention with --dist-init-addr, bind it only to a trusted interface and block those ports from anything outside the GPU cluster. Watch SGLang releases for a fix.
Primary: m00dy — Disabling Pickle did not remove Pickle (SGLang, CVE-2026-93034 / VU#765030; 7 Oct 2026) · Vendor: SGLang — GitHub releases (no fix confirmed for CVE-2026-93034 as of 9 Oct) · CVE: CVE-2026-93034 · NVD — CVE-2026-93034 (CNA CERT/CC, published 8 Oct 2026)
