Model Weight Exfiltration Vulnerability in SGLang by SGL Project
CVE-2026-15978

Currently unrated

Key Information:

Vendor

Sglang

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-15978?

SGLang introduces a vulnerability that permits remote attackers to exfiltrate model weights due to unconfigured API keys. The absence of necessary security configurations allows unauthorized access to two endpoints, enabling attackers to initiate distributed weight broadcasting with NCCL. This approach allows for data transfer that compromises the integrity of sensitive model information, putting organizations at risk of significant data breaches.

Affected Version(s)

SGLang 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.