External risk intelligence

SGLang ZMQ Remote Code Execution via Unauthenticated Pickle Deserialization

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-93034

The vulnerability involves inter-process communication using ZMQ which is typically intended for internal service communication. While it can become remotely exploitable if specific distributed settings are configured with a non-loopback address, public internet exposure is not the default or intended deployment pattern for these types of backend data-parallel attention mechanisms.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in SGLang, a technology that processes messages between different software components. The flaw allows for malicious code to be executed remotely if specific configurations related to distributed processing are enabled.

  • Flaw allows remote code execution in SGLang.
  • Critical flaw impacts messaging and data processing.
  • Confirm relevance and exposure in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted messages to a SGLang instance. If data-parallel attention is enabled and configured with a remote address, the attacker could trigger the vulnerable message decoder, leading to arbitrary code execution.

  • Entry Condition: Exposed SGLang instance with specific distributed settings.
  • Trigger Point: ZMQ message decoder unconditionally deserializes pickle payloads.
  • Resulting Risk: Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary code on a system running SGLang by sending specially crafted messages. This is possible when specific distributed settings are enabled with a non-loopback network address, potentially affecting system integrity and data confidentiality.

  • Arbitrary code execution on SGLang systems.
  • Via ZMQ message decoding and pickle deserialization.
  • Compromised system integrity and data confidentiality.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for application platforms or AI/ML infrastructure will likely need to address this vulnerability, as it affects SGLang's handling of inter-process communication. The first practical step is to identify all deployments of SGLang, determine if they are accessible externally or handle critical data, and then confirm the accountable owner before planning remediation based on the associated risk.

  • Application or AI/ML Platform owners should own the issue.
  • Verify SGLang accessibility and criticality.
  • Plan remediation based on risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SGLang and how is it used?

SGLang is a software framework designed for high-speed large language model serving and complex prompt execution. It is widely used by developers to orchestrate AI/ML workflows, often requiring efficient communication between different components of a distributed system to handle parallel processing and attention mechanisms.

What is the vulnerability in CVE-2026-93034?

This vulnerability is classified as CWE-502: Deserialization of Untrusted Data. It exists because the ZMQ message decoder processes incoming payloads using Python's pickle module without proper validation or authentication. Because pickle can execute arbitrary code during deserialization, a malicious payload can compromise the system running the software.

How can an attacker trigger this vulnerability?

The flaw is triggered when an attacker sends a specially crafted message to the SGLang service. While the decoder is always active, it becomes remotely exploitable when the system is configured for distributed operations using a non-loopback network address. Disabling specific features like SGLANG_USE_PICKLE_IPC does not prevent the issue, as the vulnerable path persists through msgpack processing.

Is my SGLang instance at risk of remote attack?

According to Halo Surface Signal, this vulnerability is most relevant if your SGLang instances are configured for data-parallel attention with remote network addresses. While ZMQ is typically intended for internal service communication, any instance exposed to untrusted network traffic with these distributed settings enabled faces a higher risk of exploitation.

What should I do to secure my environment?

Begin by auditing your infrastructure to identify all active SGLang deployments. Determine if any instances are configured with non-loopback addresses for distributed processing and verify their network accessibility. Once identified, consult your internal platform engineering team to prioritize these systems for remediation based on their exposure and the sensitivity of the data they handle.

References