A protected public chat route can coexist with execution-sensitive worker or management interfaces. The useful boundary is which actor can reach each interface and supply executable or serialization-sensitive material.
Which deployment does this concern?
CVE-2026-3059 and CVE-2026-3060 concern unsafe deserialization in enabled worker paths reachable by an attacker. CVE-2026-3989 instead requires replaying a malicious dump. The later July findings concern different endpoints and optional settings.
Affected scope: The March worker issues require multimodal generation or encoder parallel disaggregation and reachable affected channels. The July notice describes separate feature/configuration conditions without one unified version range.
Response and remediation evidence
CERT/CC’s 7 April update identifies 0.5.10 for the March findings; upstream PR #20904 records the replay-dump change. The July notice reported no patches at its publication and no vendor statement in that note. Current documentation describes API and admin keys, but documentation alone does not establish remediation of every historical path.
Remediation record: March CERT/CC update: 0.5.10, with conflicting CVE-2026-3059 metadata. A fixed release for the July group is not established by the cited July notice.
What clients can learn
Keep worker channels isolated, separate inference from administration, approve model and adapter sources, and verify the exact release and enabled endpoint inventory. Treat patch statements for different findings independently.
Keep an endpoint inventory, the effective configuration and the running artifact together. A configuration or model change should trigger a review of the boundary it changes. Assign an owner to the evidence and to any required action.
Questions for your provider
- Can an untrusted caller reach the worker or disaggregation ports?
- Which model-update, adapter, dumper and replay paths are enabled?
- Do API and admin credentials protect the intended endpoint matrix?
- Which artifact or commit proves each selected finding is remediated?
Use the inference guide and evaluation worksheet to record the answer in your deployment context.
Technical detail: source scope and identifiers
The March and July notices describe different findings. Their conditions and patch status cannot be merged into a claim about every SGLang deployment or the current release.
- CERT/CC VU#665416 covers CVE-2026-3059, CVE-2026-3060 and CVE-2026-3989. Its April update calls 0.5.10 a remediation, while the CVE-2026-3059 record has listed 0.5.10 as affected; retain both statements and request artifact-specific confirmation.
- The separate 30 July VU#281278 covers CVE-2026-15969, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977 and CVE-2026-15978. No current fixed version is inferred from that historical notice.