CVE Database
/

CVE-2026-5760

Back to search

CVE-2026-5760

Published: Apr 20, 2026

Modified: Apr 29, 2026

PUBLISHED

Description

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

VendorProductVersions

SGLang

SGLang

affected
8f3097e

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now