Database/AI/ML frameworks & serving

SGLang (encoder parallel disaggregation): Unauthenticated RCE via `pickle.loads()` in the disaggregation module
CVE-2026-3060AI/ML frameworks & servingcurated
Impact
Unauthenticated RCE via pickle.loads() in the disaggregation module
Who can reach it
Unauthenticated network on the intra-cluster fabric
What to do
Upgrade; disaggregated serving multiplies unauthenticated internal planes
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.