CVE-2026-10300: SGLang Inference HTTP Endpoint lora_manager.py assertion
A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function of the file python/sglang/srt/lora/loramanager.py of the component Inference HTTP Endpoint. Such manipulation of the argument lorapath leads to reachable assertion. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10300?
The severity of CVE-2026-10300 is low, rated at 3.7.
What components are affected by CVE-2026-10300?
CVE-2026-10300 affects the Inference HTTP Endpoint in the SGLang 0.5.10.post1 version.
How can I mitigate CVE-2026-10300?
To mitigate CVE-2026-10300, it's recommended to review and validate the inputs passed to the lora_path argument.
What kind of attack is possible with CVE-2026-10300?
CVE-2026-10300 allows for remote assertions to be triggered through manipulation of the lora_path argument.
What is the impact of CVE-2026-10300?
The impact of CVE-2026-10300 is that it may lead to application assertion failures.