mediumCVSS 5.6Vulnerability
CVE-2026-7669
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Properties
- severity
- medium
- summary
- SGLang has an Improper Input Validation/Injection Issue
- epss_score
- 0.00368
- cvss_score
- 5.6
- ghsa_published
- 2026-05-03T00:31:37Z
- source_url
- https://github.com/advisories/GHSA-6m5f-673f-5vh7
- ghsa_updated
- 2026-05-07T21:09:30Z
- ghsa_id
- GHSA-6m5f-673f-5vh7
- cve_id
- CVE-2026-7669
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.30673
Related Entities (6)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (2)
→[Weakness]Improper Input Validation
→[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]pip/sglang
AFFECTS (1)
→[Software]pip/sglang
Explore deeper with Ninja Signal's threat intelligence graph