Security Advisory

CVE-2026-15971

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 18:07:24
Last updated 2026-07-31 19:28:45
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.