SSRF and Local File Read Vulnerability in SGLang by SGL Project
CVE-2026-15974

6.5MEDIUM

Key Information:

Vendor

Sglang

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-15974?

The SGLang multimodal generation endpoint (/v1/chat/completions) is vulnerable to server-side request forgery (SSRF) and local file read due to improper sanitization of the 'image_url' parameter. This vulnerability potentially allows attackers to access internal metadata, sensitive secrets, and critical services within the network. Proper measures should be taken to sanitize inputs and protect against unauthorized access to internal systems.

Affected Version(s)

SGLang 0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.