Database/AI/ML frameworks & serving

SGLang (multimodal ZMQ broker): Unauthenticated RCE via `pickle.loads()` on the ZMQ broker
Impact
Unauthenticated RCE via pickle.loads() on the ZMQ broker
Who can reach it
Unauthenticated network from any host that can reach the broker socket
What to do
Upgrade. Providers running SGLang as a managed endpoint own this; tenants running their own own the patch but the provider owns fabric isolation
Fleet impact
How widespread
Very common - affects the disaggregated/multimodal serving paths that large GPU deployments specifically use
Cost to remediate
daemon-restart plus network re-segmentation - the ZMQ broker binds 0.0.0.0 with zero auth, so patching alone is insufficient without isolating the internal serving plane
Why it hits the whole fleet
pickle.loads() runs immediately on any payload received by an unauthenticated all-interfaces ZMQ broker, so anything with pod-network reach owns every disaggregated serving node - the multi-node serving fabric is the blast radius
References
Related entries
- SGLang (encoder parallel disaggregation): Unauthenticated RCE via `pickle.loads()` in the disaggregation moduleCVE-2026-3060 · SGLang (encoder parallel disaggregation)Critical
- LiteLLM (MCP server creation): RCE via MCP server registrationCVE-2026-30623 · LiteLLM (MCP server creation)Critical
- Kubeflow (ART component): RCE in the robustness evaluation functionCVE-2026-31228 · Kubeflow (ART component)Critical
- Kubeflow (Adversarial Robustness Toolbox component): Insecure deserialization in the Kubeflow model-loading componentCVE-2026-31229 · Kubeflow (Adversarial Robustness Toolbox component)Critical
- Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py): The ART Kubeflow evaluationCVE-2026-31230 · Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py)Critical
- llama.cpp (RPC `deserialize_tensor`): RPC backend skips all bounds validationCVE-2026-34159 · llama.cpp (RPC `deserialize_tensor`)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.