CVE-2026-105245

Summary

A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Affected Software

VendorProductVersion RangeStatus
sgl-projectsglang0.5.0affected
sgl-projectsglang0.5.1affected
sgl-projectsglang0.5.2affected
sgl-projectsglang0.5.3affected
sgl-projectsglang0.5.4affected
sgl-projectsglang0.5.5affected
sgl-projectsglang0.5.6affected
sgl-projectsglang0.5.7affected
sgl-projectsglang0.5.8affected
sgl-projectsglang0.5.9affected
sgl-projectsglang0.5.10affected
sgl-projectsglang0.5.11affected
sgl-projectsglang0.5.12affected
sgl-projectsglang0.5.13affected
sgl-projectsglang0.5.14affected
sgl-projectsglang0.5.15affected
sgl-projectsglang0.5.16affected
sgl-projectsglang0.5.17affected
sgl-projectsglang0.5.18affected
sgl-projectsglang0.5.19affected
sgl-projectsglang0.5.20affected
sgl-projectsglang0.5.21affected

Weaknesses

  • CWE-319: Cleartext Transmission of Sensitive Information
  • CWE-310: Cryptographic Issues

References