SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script. | |
| Title | CVE-2026-3989 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-03-12T11:37:48.314Z
Reserved: 2026-03-11T16:41:06.512Z
Link: CVE-2026-3989
No data.
Status : Received
Published: 2026-03-12T12:15:59.630
Modified: 2026-03-12T12:15:59.630
Link: CVE-2026-3989
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.