7.5
CVE-2026-15977
- EPSS 0.24%
- Veröffentlicht 30.07.2026 18:07:54
- Zuletzt bearbeitet 04.08.2026 20:41:20
- CVE-Watchlists
- Unerledigt
CVE-2026-15977
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.154 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://thoughts.apoorvdayal.com/posts/sglang-disclosures/
https://github.com/sgl-project/sglang/security/advisories/GHSA-jx7q-p32r-7wx8