PatchSiren cyber security CVE debrief
CVE-2026-7304 Lmsys CVE debrief
CVE-2026-7304 is a critical unauthenticated remote code execution issue in the SGLang multimodal generation runtime, published on 2026-05-18 and updated on 2026-05-19. The risk appears when `--enable-custom-logit-processor` is enabled: Python objects are deserialized through `dill.loads()` without validation, which NVD maps to CWE-502 and rates at CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H).
- Vendor
- Lmsys
- Product
- Sglang
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-19
Who should care
Operators and security teams responsible for SGLang deployments, especially internet-facing services and any environment that enables `--enable-custom-logit-processor`.
Technical summary
The vulnerable code path is gated behind `--enable-custom-logit-processor`. When that option is enabled, SGLang deserializes Python objects with `dill.loads()` without sufficient validation, creating a network-reachable unsafe deserialization path that can lead to remote code execution without authentication.
Defensive priority
Immediate
Recommended defensive actions
- Check whether any SGLang deployment enables `--enable-custom-logit-processor`; treat exposed instances as high priority.
- Disable the custom logit processor option wherever it is not strictly required.
- If the feature must remain in use, isolate the service, restrict network exposure, and limit who can reach it.
- Track the official CVE/NVD records and vendor guidance for remediation updates before re-enabling the feature.
- Review logs and adjacent services for unexpected behavior on deployments that used the affected option.
Evidence notes
The supplied official NVD record describes the issue as unauthenticated remote code execution in SGLang and lists CWE-502 with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD also lists `cpe:2.3:a:lmsys:sglang:0.5.10` as vulnerable. The CERT-referenced blog post and the linked SGLang repository provide context on the affected project codebase; no fixed version or patch details were present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7304 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7304
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7304 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7304
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://antiproof.ai/blog/three-rces-in-sglang/
[email protected] - Permissions Required
-
Source reference
Unverified legacy reference
URL: https://github.com/sgl-project/sglang/tree/main/python/sglang
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.