CVE-2026-93034: SGLang SGLang vulnerability
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in maybeunwrappickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANGUSEPICKLEIPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.