VulnWatch VulnWatch
← Back to dashboard
Unknown nvd · CVE-2026-15969

CVE-2026-15969: SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl

Published Jul 30, 2026

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

Affected AI Products

sglang
Get the weekly digest. Every Monday: top AI security stories of the week. Free.