CVE-2026-3060 | SGLang up to 0.5.9 Disaggregation pickle.loads deserialization
A vulnerability classified as critical was found in SGLang up to 0.5.9. Affected by this vulnerability is the function pickle.loads of the component Disaggregation Module. The manipulation results in deserialization.
This vulnerability was named CVE-2026-3060. The attack may be performed from remote. There is no available exploit.