VU#777338: SGLang contains two remote code execution and one path traversal vulnerability

2026-05-20T20:52:11Zdfe223062c1f9ebee8cc03ea16103325ca6274c5833e9d645b8bad881c505cfd
AF_ALG/Copy-FailCERT/CC advisoryarbitrary file writecross-site scriptingdeserializationdilldns poisoningheap overflowinformation disclosurelocal privilege escalationmemory corruptionmodel upload/quantizationpath traversalpickleremote code executionunauthenticated configuration modification

What happened

This document aggregates multiple CERT/CC vulnerability advisories (May 2026) covering several high-impact issues across different projects: SGLang (unauthenticated deserialization RCEs via pickle/dill and a path traversal arbitrary write when multimodal generation is enabled; no patch available), dnsmasq (multiple memory-safety flaws enabling DNS cache poisoning, DoS, info disclosure and under some conditions local root/code execution; fixed in 2.92rel2), Casdoor (authenticated arbitrary file write via path traversal in Local File System storage provider, CVE-2026-6815), the Linux kernel “Co

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
dfe223062c1f9ebee8cc03ea16103325ca6274c5833e9d645b8bad881c505cfd
Enrichment time
2026-05-20T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.