CVE-2026-14890 – SGLang
CVSS 9.1
CRITICAL
Critical - Same Day Deployment
“An exposed service without authentication can turn a single network connection into a complete compromise.”
A patch is available for CVE-2026-14890, a critical vulnerability affecting SGLang. The vulnerability exists in the expert-parallel backup subsystem, which exposes a ZeroMQ PULL socket on a routable network interface without authentication or deserialization protections. An attacker can provide a malicious pickle file, resulting in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
The CVSS score is 9.1, which is Critical severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.
Key Details
- Affected Product
- Lmsys Sglang
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-502
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.