What is CVE-2026-15971?
CVE-2026-15971 is an RCE vulnerability in the SGLang platform when the optional dumper subsystem is enabled, triggered by setting DUMPER_SERVER_PORT. It allows sandbox escape and code execution via inference requests, posing a critical risk if exposed to untrusted networks.
Azərbaycanca: CVE-2026-15971 SGLang platformasında əlavə dumper alt sistemi aktiv olduqda (DUMPER_SERVER_PORT parametri təyin edildikdə) ortaya çıxan uzaqdan kod icrası (RCE) zəifliyidir. Bu boşluq sandbox qaçışına səbəb olaraq inference sorğuları vasitəsilə kod icrasına imkan yaradır. İstifadəçilər DUMPER_SERVER_PORT parametrinin yalnız etibarlı mühitlərdə aktiv olduğundan əmin olmalıdırlar.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Under what conditions is CVE-2026-15971 triggered in the SGLang platform?
The vulnerability surfaces when the optional dumper subsystem is enabled by setting the DUMPER_SERVER_PORT parameter.
What can an attacker achieve by exploiting this vulnerability?
An attacker can achieve sandbox escape and perform remote code execution (RCE) through inference requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.