VulnWatch VulnWatch
← Back to dashboard
Unknown nvd · CVE-2026-15971

CVE-2026-15971: SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D

Published Jul 30, 2026

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.

Affected AI Products

sglang
Get the weekly digest. Every Monday: top AI security stories of the week. Free.