LIVE · cybersecurity feed
Live wire
vendor

Lmsys

12 CVEs published in the last four months. Exploited flaws first.

Critical9
High3
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-159769.8criticalsglangSGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifica37d ago
CVE-2026-30599.8criticalsglangSGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker177d ago
CVE-2026-30609.8criticalsglangSGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the d177d ago
CVE-2026-73019.8criticalsglangSGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink tha110d ago
CVE-2026-159699.8criticalsglangSGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete37d ago
CVE-2026-159719.8criticalsglangSGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape 37d ago
CVE-2026-73049.8criticalsglangSGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-cust110d ago
CVE-2026-73029.1criticalsglangSGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an110d ago
CVE-2026-148909.1criticalsglangSGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface 51d ago
CVE-2026-39897.8highsglangSGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization.177d ago
CVE-2026-159777.5highsglangSGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SS37d ago
CVE-2026-159787.5highsglangSGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose t37d ago

Filter the full tracker by Lmsys