External risk intelligence

SGLang Pickle Deserialization Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-86793

SGLang is typically deployed as a model serving framework or API endpoint to facilitate AI model inference. As an API service designed to handle requests for model weights and interactions, it is commonly exposed as an internet-facing service or an edge component within application infrastructure to be reachable by clients.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves SGLang, a technology used for AI model serving. It allows unauthenticated access to execute arbitrary code on systems if certain security configurations are not in place. The primary concern is confirming if your AI model serving infrastructure is impacted and to what extent.

  • Unauthenticated code execution in AI model serving.
  • Confirms exposure and relevance for AI infrastructure.
  • Assess your AI serving environment for this risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to an SGLang server that is not configured with authentication keys. This request would target the `/update_weights_from_tensor` endpoint, triggering a bypass of the SafeUnpickler policy. By manipulating the pickle deserialization process, an attacker could achieve code execution on the affected server.

  • No authentication required.
  • Triggered by unauthenticated pickle deserialization.
  • Allows unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When SGLang is deployed without authentication, unauthenticated attackers could execute arbitrary code on the server by sending specially crafted pickle data through the `/update_weights_from_tensor` endpoint. This could occur if the SafeUnpickler policy is bypassed, allowing malicious commands to be run.

  • Arbitrary code execution on the server.
  • Unauthenticated network access to the API.
  • Compromise of the AI model serving infrastructure.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical vulnerability in SGLang affecting unauthenticated pickle deserialization requires immediate attention from teams responsible for AI model serving infrastructure. The first practical step is to identify all SGLang deployments, confirm their exposure and business criticality, and then assign ownership for remediation planning.

  • Platform or application owners should investigate.
  • Verify unauthenticated access to `/update_weights_from_tensor`.
  • Plan coordinated vendor engagement and remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SGLang?

SGLang is a software framework designed for high-performance large language model serving. It provides an API infrastructure that handles model inference, allowing developers to manage interactions and dynamic weight updates for AI models efficiently.

What does CWE-94 mean in the context of CVE-2026-86793?

CWE-94 refers to Improper Control of Generation of Code. In this CVE, the vulnerability allows the system to deserialize untrusted data via the pickle module. Because the safety policy fails to block dangerous functions like import or getattr, an attacker can manipulate the process to execute unauthorized commands on the server.

How is this vulnerability triggered?

An attacker triggers the bug by sending a specially crafted request to the /update_weights_from_tensor endpoint. This exploit path only functions if the SGLang server is running without configured authentication keys; systems that have correctly implemented authentication are not susceptible to this specific remote trigger.

Who is at risk according to Halo Surface Signal?

Organizations using SGLang as an internet-facing API service or as an edge component are at higher risk. Halo Surface Signal identifies this as a critical concern because these deployments are often intentionally reachable by external clients to facilitate AI model inference, making them visible and accessible to unauthorized network traffic.

Do I need to take action if I run SGLang?

Yes. You should immediately identify all active SGLang instances to verify if they are running without authentication. Coordinate with your engineering team to confirm if the /update_weights_from_tensor endpoint is accessible to unauthorized users and prioritize planning a secure configuration or update to mitigate the risk of remote code execution.

References