Home 0.5.5 (custom)
affected
Description
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.
Problem types
CWE-502: Deserialization of Untrusted Data
Product status
References
github.com/...n/sglang/srt/disaggregation/encode_receiver.py
orca.security/...g/sglang-llm-framework-rce-vulnerabilities/