CVE-2026-3989 | SGLang up to 0.5.9 replay_request_dump.py pickle.load deserialization
A vulnerability, which was classified as critical, was found in SGLang up to 0.5.9. This affects the function pickle.load of the file replay_request_dump.py. Such manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-3989. It is possible to launch the attack remotely. No exploit is available.