SSRF and Local File Read Vulnerability in SGLang by SGL Project
CVE-2026-15974

Currently unrated

Key Information:

Vendor

Sglang

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-15974?

The SGLang multimodal generation endpoint (/v1/chat/completions) is vulnerable to server-side request forgery (SSRF) and local file read due to improper sanitization of the 'image_url' parameter. This vulnerability potentially allows attackers to access internal metadata, sensitive secrets, and critical services within the network. Proper measures should be taken to sanitize inputs and protect against unauthorized access to internal systems.

Affected Version(s)

SGLang 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.