CVE-2026-7304
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/05/2026
Last modified:
18/05/2026
Description
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.



