A vulnerability was found in SGLang 5.10 and classified as critical . This vulnerability affects the function dill.loads . Such manipulation leads to deserialization. This vulnerability is documented as CVE-2026-7304 . The attack can be executed remotely. There is not any exploit available.