CVE-2026-15969: Critical severity SGLang vulnerability
SGLang contains an unauthenticated RCE in /loadloraadapterfromtensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15969?
CVE-2026-15969 has a risk rating of 95, indicating a critical severity due to its ability to allow remote code execution.
How do I fix CVE-2026-15969?
To mitigate CVE-2026-15969, update SGLang to the latest version where the vulnerability is patched.
What is CVE-2026-15969?
CVE-2026-15969 describes a vulnerability in SGLang that allows unauthenticated remote code execution through a bypass of the SafeUnpickler denylist.
Which component of SGLang is affected by CVE-2026-15969?
CVE-2026-15969 specifically affects the /load_lora_adapter_from_tensors function in SGLang.
Can CVE-2026-15969 be exploited remotely?
Yes, CVE-2026-15969 can be exploited remotely through crafted base64-encoded pickle payloads.