{"api_version":"v1","generated_at":"2026-10-09T09:00:00+00:00","product":{"cve_count":18,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-sglang-sglang-755facadfca1","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"SGLang","next_cursor":null,"observations":[{"affected":"SGLang: \u2264 v0.5.20","affected_versions_present":true,"cve_id":"CVE-2026-93034","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-93034","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-08T20:22:35.805Z","patch_url":"","primary_source":"","published":"2026-10-08T14:00:09.084Z"},{"affected":"SGLang: \u2264 0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-94570","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94570","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-22T14:56:04.582Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-94570","primary_source":"","published":"2026-09-22T14:15:00.885Z"},{"affected":"SGLang: 0.5.11 \u2264 0.5.14","affected_versions_present":true,"cve_id":"CVE-2026-93088","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-93088","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-22T18:45:48.365Z","patch_url":"","primary_source":"","published":"2026-09-22T14:07:45.629Z"},{"affected":"SGLang: \u2264 0.5.18","affected_versions_present":true,"cve_id":"CVE-2026-86793","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86793","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T18:51:51.052Z","patch_url":"","primary_source":"","published":"2026-09-11T11:35:20.812Z"},{"affected":"\u2264 v0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-15969","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15969","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T17:37:45.471Z","patch_url":"https://thoughts.apoorvdayal.com/posts/sglang-disclosures/","primary_source":"","published":"2026-07-30T18:09:21.005Z"},{"affected":"\u2264 v0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-15978","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15978","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T18:10:22.232Z","patch_url":"https://thoughts.apoorvdayal.com/posts/sglang-disclosures/","primary_source":"","published":"2026-07-30T18:08:29.228Z"},{"affected":"\u2264 v0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-15977","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15977","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T19:08:46.654Z","patch_url":"https://thoughts.apoorvdayal.com/posts/sglang-disclosures/","primary_source":"","published":"2026-07-30T18:07:54.911Z"},{"affected":"\u2264 v0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-15976","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15976","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T19:11:57.388Z","patch_url":"https://thoughts.apoorvdayal.com/posts/sglang-disclosures/","primary_source":"","published":"2026-07-30T18:07:44.256Z"},{"affected":"\u2264 v0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-15974","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15974","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T19:25:43.419Z","patch_url":"https://thoughts.apoorvdayal.com/posts/sglang-disclosures/","primary_source":"","published":"2026-07-30T18:07:35.029Z"},{"affected":"\u2264 v0.5.15","affected_versions_present":true,"cve_id":"CVE-2026-15971","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-15971","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-31T19:28:45.016Z","patch_url":"https://thoughts.apoorvdayal.com/posts/sglang-disclosures/","primary_source":"","published":"2026-07-30T18:07:24.451Z"},{"affected":"\u2264 0.5.14","affected_versions_present":true,"cve_id":"CVE-2026-14890","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14890","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-16T18:23:35.561Z","patch_url":"https://www.kb.cert.org/vuls/id/326070","primary_source":"","published":"2026-07-16T14:43:44.087Z"},{"affected":"5.10","affected_versions_present":true,"cve_id":"CVE-2026-7304","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7304","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-18T14:04:23.864Z","patch_url":"","primary_source":"","published":"2026-05-18T10:39:52.696Z"},{"affected":"5.10","affected_versions_present":true,"cve_id":"CVE-2026-7302","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7302","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-18T14:05:33.942Z","patch_url":"","primary_source":"","published":"2026-05-18T10:39:27.474Z"},{"affected":"5.10","affected_versions_present":true,"cve_id":"CVE-2026-7301","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7301","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-18T14:06:20.513Z","patch_url":"","primary_source":"","published":"2026-05-18T10:38:56.493Z"},{"affected":"8f3097e","affected_versions_present":true,"cve_id":"CVE-2026-5760","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5760","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-29T13:23:42.103Z","patch_url":"https://github.com/sgl-project/sglang/pull/23660","primary_source":"","published":"2026-04-20T13:46:23.603Z"},{"affected":"0.5.10","affected_versions_present":true,"cve_id":"CVE-2026-3989","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3989","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-07T18:46:48.636Z","patch_url":"https://github.com/sgl-project/sglang/pull/20904","primary_source":"","published":"2026-03-12T11:37:48.314Z"},{"affected":"0.5.10","affected_versions_present":true,"cve_id":"CVE-2026-3060","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3060","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-07T18:45:35.370Z","patch_url":"https://orca.security/resources/blog/sglang-llm-framework-rce-vulnerabilities/","primary_source":"","published":"2026-03-12T11:37:37.009Z"},{"affected":"0.5.10","affected_versions_present":true,"cve_id":"CVE-2026-3059","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3059","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-07T18:46:03.195Z","patch_url":"https://orca.security/resources/blog/sglang-llm-framework-rce-vulnerabilities/","primary_source":"","published":"2026-03-12T11:37:25.713Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"SGLang"}}
