CVE-2026-3989EPSS p35.0%

CVE-2026-3989CVE-2026-3989

lmsys / sglang

Description

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

Scoring

CVSS 7.8 ()
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.43% probability of exploitation · percentile 35.0% · 2026-10-05T12:00:23Z
Last modified2026-08-10
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.