Model Weight Exfiltration Vulnerability in SGLang by SGL Project
CVE-2026-15978

7.5HIGH

Key Information:

Vendor

Sglang

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-15978?

SGLang introduces a vulnerability that permits remote attackers to exfiltrate model weights due to unconfigured API keys. The absence of necessary security configurations allows unauthorized access to two endpoints, enabling attackers to initiate distributed weight broadcasting with NCCL. This approach allows for data transfer that compromises the integrity of sensitive model information, putting organizations at risk of significant data breaches.

Affected Version(s)

SGLang 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.