← Back to search

CVE-2026-93088

9.8 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
The vulnerability allows unauthenticated attackers to execute arbitrary code by exploiting the unvalidated handling of multipart messages in the DiffusionServer.
Exploitability
Exploitation is relatively straightforward given the unauthenticated nature and direct deserialization of received messages.
Blast radius
If exploited, this could lead to complete compromise of the affected system, potentially allowing attackers to gain full control over the server.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the DiffusionServer endpoint.
rceunauthcode-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.