Feed/CVE-2026-15971
CVE-2026-15971CRITICALCVSS 9.8

CVE-2026-15971

Published Jul 30, 2026·Updated Aug 4, 2026

NVD Description

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free