External risk intelligence

SGLang Multimodal Runtime Pickle Deserialization Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-93088

The vulnerability involves a ZeroMQ ROUTER socket used in a disaggregated-diffusion orchestrator. While network-reachable, this component is typically part of a backend infrastructure or internal cluster communication rather than a public-facing web gateway or edge service. Public exposure is possible depending on deployment configuration, but it is not a standard internet-facing design.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in SGLang's multimodal generation runtime, specifically within the disaggregated-diffusion orchestrator. This issue allows for unauthenticated arbitrary code execution due to the way network messages are processed, potentially exposing systems to significant risk if not properly assessed. The main concern is confirming relevance and exposure within our environment.

  • Unauthenticated code execution in SGLang runtime.
  • Critical risk if present; confirm relevance and exposure.
  • Understand potential impact to our systems.

Attack Path

How an attacker could exploit the issue

An attacker could gain control by sending specially crafted messages over the network to a SGLang multimodal generation runtime. The runtime's diffusion orchestrator uses a network service that accepts these messages without checking who sent them. It then processes the messages in a way that allows arbitrary code to be executed on the affected system, potentially leading to a complete compromise.

  • Network access required.
  • Unauthenticated network messages trigger.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

SGLang's multimodal generation runtime could allow unauthenticated arbitrary code execution when its diffusion orchestrator binds an unauthenticated ZeroMQ socket to a network interface. This could affect the system's integrity and confidentiality when processing multipart messages without prior validation.

  • Arbitrary code execution on the system.
  • Unauthenticated network message processing.
  • Potential for system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership of this vulnerability likely falls to the teams managing the SGLang deployment, potentially the platform or infrastructure team responsible for the multimodal generation runtime. The immediate first step is to identify all instances of the affected technology, confirm their network exposure and business criticality, and then assign an accountable owner for remediation planning.

  • Platform/Infrastructure team owns the issue.
  • Verify network exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the SGLang multimodal generation runtime?

SGLang is an open-source framework designed to accelerate and optimize Large Language Model (LLM) serving. Its multimodal generation runtime includes components like the disaggregated-diffusion orchestrator, which helps manage and scale the complex computational tasks required to generate images or other non-text data from prompts.

What does CWE-502 mean in the context of CVE-2026-93088?

CWE-502 refers to 'Deserialization of Untrusted Data.' In this vulnerability, the system uses the pickle library to process incoming network messages without first validating them. Since pickle can be instructed to run arbitrary commands during the loading process, an attacker can use this to execute malicious code on the host system.

How is this vulnerability triggered?

The flaw is triggered when an attacker sends a specially crafted multipart message to the ZeroMQ socket used by the DiffusionServer. It is important to note that sending legitimate, non-malicious orchestration traffic or interacting with other parts of the SGLang stack that do not utilize this specific insecure socket will not trigger this code execution path.

Is my instance affected by this vulnerability?

According to Halo Surface Signal, this vulnerability impacts network-reachable components. While the DiffusionServer uses a ZeroMQ socket typically reserved for internal cluster communication, your specific deployment configuration determines if that socket is exposed to untrusted networks. You should prioritize checking if your orchestrator is accessible beyond your internal infrastructure.

How should I respond if I use SGLang?

Your first step is to locate all deployments of the SGLang multimodal runtime within your environment. Once identified, evaluate the network boundaries of each instance to confirm if the orchestrator is reachable from outside your trusted network. Work with your platform or infrastructure teams to restrict access to the affected socket while preparing for a permanent security update.

References