CVE-2026-3059 | SGLang up to 0.5.9 ZMQ Broker pickle.loads deserialization (GHSA-3cp7-c6q2-94xr)
A vulnerability classified as critical has been found in SGLang up to 0.5.9. Affected is the function pickle.loads of the component ZMQ Broker. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-3059. The attack is possible to be carried out remotely. No exploit exists.