SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-14890

CRITICAL · CVSS 9.1 EPSS 0.91% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in SGLang stems from an exposed ZeroMQ PULL socket on a routable network interface, lacking authentication and deserialization protections. This flaw allows attackers to execute arbitrary code remotely by sending a malicious pickle file, posing a critical risk to systems where this feature is enabled and accessible over the network. Organizations utilizing SGLang should prioritize immediate remediation efforts to mitigate the potential for unauthorized access and exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14890
Severity
CRITICAL
CVSS
9.1
EPSS
0.91%

Original NVD Description

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)