Database/AI/ML frameworks & serving

SGLang (encoder parallel disaggregation): Unauthenticated RCE via `pickle.loads()` in the disaggregation module
CVSS 9.8CVE-2026-3060AI/ML frameworks & servingcurated
Impact
Unauthenticated RCE via pickle.loads() in the disaggregation module
Who can reach it
Unauthenticated network on the intra-cluster fabric
What to do
Upgrade; disaggregated serving multiplies unauthenticated internal planes
References
Related entries
- LiteLLM (MCP server creation): RCE via MCP server registrationCVE-2026-30623 · LiteLLM (MCP server creation)Critical
- Kubeflow (ART component): RCE in the robustness evaluation functionCVE-2026-31228 · Kubeflow (ART component)Critical
- Kubeflow (Adversarial Robustness Toolbox component): Insecure deserialization in the Kubeflow model-loading componentCVE-2026-31229 · Kubeflow (Adversarial Robustness Toolbox component)Critical
- Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py): The ART Kubeflow evaluationCVE-2026-31230 · Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py)Critical
- llama.cpp (RPC `deserialize_tensor`): RPC backend skips all bounds validationCVE-2026-34159 · llama.cpp (RPC `deserialize_tensor`)Critical
- Apache OpenNLP: model archive manifest names any classpath class and runs its static initializerCVE-2026-42027 · Apache OpenNLP ExtensionLoader (model archive manifest.properties)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.