VU#777338: SGLang contains two remote code execution and one path traversal vulnerability

2026-05-18T20:52:08Z72255e9d5ca926938e2618403c7f2ae8374cb7d9ea6f98e22ae433553968c0b4
AF_ALGCasdoorDRC-INSIGHTGGUFLinux-kernelOllamaRadware-AlteonSGLangarbitrary-file-writeauthenticateddenial-of-servicedeserializationdilldnsmasqfile-uploadheap-overflowinformation-disclosurelocal-privilege-escalationmemory-corruptionmodel-quantizationpath-traversalpickleremote-code-executionunauthenticatedxss

What happened

This feed summarizes multiple distinct vulnerabilities disclosed in May 2026 affecting several open-source and commercial products. Notable issues include: (1) SGLang multimodal runtime RCEs (pickle/dill deserialization) and a path-traversal arbitrary-file-write vector exposed by default (CVE-2026-7301, CVE-2026-7304, CVE-2026-7302); (2) multiple memory-safety and DNS/DHCP flaws in dnsmasq allowing DNS cache poisoning, DoS, information disclosure, and possible local code execution (CVE-2026-2291, CVE-2026-4890/4891/4892/4893, CVE-2026-5172) — fixed in dnsmasq 2.92rel2; (3) Casdoor local file‑s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
72255e9d5ca926938e2618403c7f2ae8374cb7d9ea6f98e22ae433553968c0b4
Enrichment time
2026-05-18T20:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#777338: SGLang contains two remote code execution and one path traversal vulnerability · Baitaphish