CVE-2026-7304

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/05/2026
Last modified:
18/05/2026

Description

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.

Impact