A vulnerability was found in SGLang 5.10 . It has been rated as critical . The affected element is the function pickle.loads of the component Incoming Message Handler . The manipulation leads to deserialization. This vulnerability is traded as CVE-2026-7301 . It is possible to initiate the attack remotely. There is no exploit available.