CVE-2026-5760: exploitation status and patch state
CVE-2026-5760 · CVSS 9.8 CRITICAL
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().
Is CVE-2026-5760 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.