VU#915947: SGLang is vulnerable to remote code execution when rendering chat templates from a model file
2026-04-20T20:52:11Z•07a1bc6a8825e2ec733af946d67c14b2c2a57ac033f485ce3e9061b4471ef8fb
Code InterpreterCrewAIDICOMGGUFIDriveJinja2KubernetesKyvernoLLM servingMuPDFOrthancSSRFSSRF chainingSSTIWindows LPEZIP memory exhaustionadmission controllerdefault credentials (hardcoded)gzip decompression bombharborheap buffer overflowinteger overflowlocal privilege escalationmodel poisoningremote code execution
What happened
The document aggregates multiple high-impact vulnerabilities across open-source and commercial projects. Notable issues include: SGLang remote code execution via a malicious GGUF model using a Jinja2 SSTI in tokenizer.chat_template that results in server-side RCE (CVE-2026-5760); multiple Orthanc DICOM vulnerabilities (heap buffer overflows, out-of-bounds reads, decompression/ZIP memory exhaustion) that can crash servers, leak memory, or enable code execution (CVE-2026-5437, CVE-2026-5438, CVE-2026-5439); an integer overflow in MuPDF leading to heap corruption and possible code execution (CVE-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 07a1bc6a8825e2ec733af946d67c14b2c2a57ac033f485ce3e9061b4471ef8fb
- Enrichment time
- 2026-04-20T20:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.