CVE-2026-15971: SGLang contains an RCE vulnerability when the optional
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.
- EPSS 0.4% (33.2% percentile)
- CVSS 9.8 critical