CVE-2026-15971 | SGLang up to 0.5.15 Dumper Subsystem DUMPER_SERVER_PORT eval injection

SecurityVulns

A vulnerability marked as critical has been reported in SGLang up to 0.5.15. This impacts an unknown function of the component Dumper Subsystem. The manipulation of the argument DUMPER_SERVER_PORT leads to improper neutralization of directives in dynamically evaluated code.

This vulnerability is traded as CVE-2026-15971. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More