CVE-2026-10775
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component
CVSS
3.6
Bajo
EPSS
0.1%
p2
KEV
—
Exploit Today
1
0-100
Publicado: 3 jun 2026 · Última mod.: 22 jul 2026 · CWE-404
0.1%EPSS · 30 días0.1%
2026-06-302026-07-23
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
- github.comhttps://github.com/sgl-project/sglang/
- github.comhttps://github.com/sgl-project/sglang/issues/25462
- github.comhttps://github.com/sgl-project/sglang/pull/22033
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10775
- vuldb.comhttps://vuldb.com/submit/831438
- vuldb.comhttps://vuldb.com/vuln/368138
- vuldb.comhttps://vuldb.com/vuln/368138/cti
- github.comhttps://github.com/sgl-project/sglang/pull/22033
- vuldb.comhttps://vuldb.com/submit/831438
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-156903.1 BAJ34.3%
——10A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference. The attack can be executed remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit is publicly available and might be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.9dCVE-2026-152763.3 BAJ2.2%
——1A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.13dCVE-2026-152743.3 BAJ2.2%
——1A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. The manipulation results in denial of service. The attack must be initiated from a local position. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.13dCVE-2026-151843.3 BAJ2.0%
——1A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be used. Upgrading to version 0.14 is sufficient to resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is recommended. Different than CVE-2026-9503.14dCVE-2026-597257.5 ALT27.9%
——8Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust server-side connections and sockets. This issue is fixed in version 6.6.7.10dCVE-2026-148013.3 BAJ1.6%
——0A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argument txml_timescale leads to divide by zero. An attack has to be approached locally. The name of the patch is 86a5191f2e750c767253e27ed6cfd6d547afebc2. A patch should be applied to remediate this issue.17d