VU#777338: SGLang contains two remote code execution and one path traversal vulnerability
2026-05-18T20:52:08Z•72255e9d5ca926938e2618403c7f2ae8374cb7d9ea6f98e22ae433553968c0b4
AF_ALGCasdoorDRC-INSIGHTGGUFLinux-kernelOllamaRadware-AlteonSGLangarbitrary-file-writeauthenticateddenial-of-servicedeserializationdilldnsmasqfile-uploadheap-overflowinformation-disclosurelocal-privilege-escalationmemory-corruptionmodel-quantizationpath-traversalpickleremote-code-executionunauthenticatedxss
What happened
This feed summarizes multiple distinct vulnerabilities disclosed in May 2026 affecting several open-source and commercial products. Notable issues include: (1) SGLang multimodal runtime RCEs (pickle/dill deserialization) and a path-traversal arbitrary-file-write vector exposed by default (CVE-2026-7301, CVE-2026-7304, CVE-2026-7302); (2) multiple memory-safety and DNS/DHCP flaws in dnsmasq allowing DNS cache poisoning, DoS, information disclosure, and possible local code execution (CVE-2026-2291, CVE-2026-4890/4891/4892/4893, CVE-2026-5172) — fixed in dnsmasq 2.92rel2; (3) Casdoor local file‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 72255e9d5ca926938e2618403c7f2ae8374cb7d9ea6f98e22ae433553968c0b4
- Enrichment time
- 2026-05-18T20:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.