What is CVE-2026-15969?
An unauthenticated Remote Code Execution (RCE) vulnerability exists in SGLang, specifically in the /load_lora_adapter_from_tensors endpoint. This is achieved by bypassing SafeUnpickler's incomplete denylist using crafted base64-encoded pickle payloads. Immediate update to the latest version is recommended.
Azərbaycanca: SGLang-da autentifikasiya olunmadan uzaqdan kod icrası (RCE) zəifliyi aşkar edilib. Bu, /load_lora_adapter_from_tensors endpoint-ində SafeUnpickler-in qeyri-kamil qadağa siyahısının bypass edilməsi ilə baş verir. Təcili olaraq SGLang-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
What risk does CVE-2026-15969 pose in SGLang?
CVE-2026-15969 is a critical vulnerability in SGLang that allows unauthenticated Remote Code Execution (RCE). It occurs due to bypassing `SafeUnpickler`'s incomplete denylist via crafted base64-encoded pickle payloads on the `/load_lora_adapter_from_tensors` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.