VU#915947: SGLang is vulnerable to remote code execution when rendering chat templates from a model file

2026-04-20T20:52:11Z07a1bc6a8825e2ec733af946d67c14b2c2a57ac033f485ce3e9061b4471ef8fb
Code InterpreterCrewAIDICOMGGUFIDriveJinja2KubernetesKyvernoLLM servingMuPDFOrthancSSRFSSRF chainingSSTIWindows LPEZIP memory exhaustionadmission controllerdefault credentials (hardcoded)gzip decompression bombharborheap buffer overflowinteger overflowlocal privilege escalationmodel poisoningremote code execution

What happened

The document aggregates multiple high-impact vulnerabilities across open-source and commercial projects. Notable issues include: SGLang remote code execution via a malicious GGUF model using a Jinja2 SSTI in tokenizer.chat_template that results in server-side RCE (CVE-2026-5760); multiple Orthanc DICOM vulnerabilities (heap buffer overflows, out-of-bounds reads, decompression/ZIP memory exhaustion) that can crash servers, leak memory, or enable code execution (CVE-2026-5437, CVE-2026-5438, CVE-2026-5439); an integer overflow in MuPDF leading to heap corruption and possible code execution (CVE-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
07a1bc6a8825e2ec733af946d67c14b2c2a57ac033f485ce3e9061b4471ef8fb
Enrichment time
2026-04-20T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.