Vulnerability intelligence
CVE-2026-14890
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.7%
Riskier than 50% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 23, 2026 · latest Jul 23, 2026
Coverage timeline
-
Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Executionsecurityonline.info · Jul 23, 2026