A bypass of SGLang’s pickle filter

SGLang, the open-source framework used to serve large language models, can be made to run an attacker’s code through an HTTP endpoint that requires no credentials in its default state, VicOne disclosed on 11 September. The flaw, CVE-2026-86793, was published the same day by CERT/CC, and no fixed version has been named.

The problem is in /update_weights_from_tensor. VicOne researcher Reuel Magistrado found that the endpoint is marked AuthLevel.ADMIN_OPTIONAL: when neither an API key nor an admin API key is configured, it accepts requests without authentication. Anyone who can reach the server can send it a POST request carrying a base64-encoded pickle payload.

SGLang is meant to stop malicious pickles with SafeUnpickler, a filter introduced to mitigate an earlier deserialisation flaw, CVE-2025-10164. According to VicOne, its allowlist admits anything under the broad prefix builtins., and its denylist blocks eval, exec, compile and open but not __import__ or getattr. Chained together, those two functions reach any function in any importable module.

Fibre-optic cables plugged into a patch panel
Fibre-optic cabling in a data centre. Stock photo. Brett Sayles · pexels · Pexels License

No patch, and two version ranges

VicOne’s timeline shows a long wait. It reported the flaw to the maintainers on 29 June, got an acknowledgement over Slack on 2 July, escalated to CERT/CC on 16 July, and CERT/CC validated it on 30 July. The CVE was assigned on 8 September. As of publication, VicOne wrote, the maintainers had acknowledged the report but had not provided a patch or a remediation timeline.

The sources disagree on scope. VicOne’s post lists SGLang 0.5.14 and earlier; the CVE record lists every version through 0.5.18. SGLang 0.5.19 appeared on PyPI on 4 September, a week before disclosure, but neither VicOne nor the CVE record says that release addresses the flaw. The record carries no CVSS score yet.

It is not the first time the filter has been beaten. CVE-2026-15969, published on 30 July with a CVSS 3.1 score of 9.8, described unauthenticated code execution through a different endpoint, /load_lora_adapter_from_tensors, via a bypass of SafeUnpickler’s incomplete denylist.

VicOne’s advice is to enable authentication and to restrict access to the affected endpoint to trusted networks.

Google’s ADK: rated 10.0, already fixed

The second flaw is in Google’s Agent Development Kit for Python. CVE-2026-79696, published on 9 September with Google Cloud as the numbering authority, carries the maximum CVSS 4.0 score of 10.0. It affects adk web in ADK versions 2.0.0 through 2.6.0 on Python, Cloud Run and GKE environments where pytest is installed, and lets an unauthenticated remote attacker execute arbitrary code using a crafted test session replay.

Google attributes the flaw to an incomplete standard-library denylist and credits Sanil Dulal with the report. The fix commit the record points to says the old denylist missed modules such as cProfile, bdb, trace and timeit, which can execute arbitrary strings, and now blocks the whole standard library in agent-config code references.

A developer typing code on a laptop
A developer working on code. Stock photo. cottonbro studio · pexels · Pexels License

Unlike SGLang, this one is patched. The fix shipped in ADK 2.7.0 on 13 August, almost four weeks before the CVE was published, and OSV lists 2.7.0 as the first fixed version. Google’s guidance is to upgrade to google-adk 2.7.0 or later and not to expose adk web to a network. The 2.7.0 release notes also state that the adk web and API servers are unauthenticated and local-only.

Part of a pattern

Forkast counts four critical CVEs in AI inference and agent infrastructure in four weeks: NemoClaw (CVE-2026-65105, 25 August), DeepSeek Harness (CVE-2026-82533, 8 September), IBM Langflow (CVE-2026-81204, 8 September) and SGLang. It argues disclosures have reached about one a week in the third quarter of 2026, against roughly one a month in 2025, and blames components built for ease of integration rather than strict access control. The ADK flaw is not part of that tally.

What to watch

The open question is whether SGLang’s maintainers ship a release that closes the bypass, and whether it narrows SafeUnpickler’s builtins. allowlist, requires authentication on ADMIN_OPTIONAL endpoints by default, or both. Until a fixed version is named, VicOne’s mitigation of authentication plus network restriction is the only defence it offers.