CVE-2026-14890 – SGLang

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“An exposed service without authentication can turn a single network connection into a complete compromise.”

A patch is available for CVE-2026-14890, a critical vulnerability affecting SGLang. The vulnerability exists in the expert-parallel backup subsystem, which exposes a ZeroMQ PULL socket on a routable network interface without authentication or deserialization protections. An attacker can provide a malicious pickle file, resulting in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.

The CVSS score is 9.1, which is Critical severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Key Details

Affected Product
Lmsys Sglang
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-502
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.