Description
A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.
Published: 2026-10-05
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive data exposure via cleartext transmission
Action: Assess Impact
AI Analysis

Impact

The flaw resides in sgllang’s HTTP Endpoint server_info function, where a manipulation of the api_key argument results in sensitive information being sent in cleartext. The weakness falls under the categories of transmitting data without encryption (CWE-310) and transmitting data over an insecure channel (CWE-319). As a consequence, an attacker could obtain confidential data without needing to compromise the underlying system. The impact is limited to confidentiality; there is no mention of integrity or availability damage.

Affected Systems

The vulnerability affects the sgl-project sglang component through version 0.5.21. Users deploying any of these releases—and especially those exposing the HTTP endpoint to external networks—are at risk.

Risk and Exploitability

The CVSS score of 6.3 assigns a moderate severity, while the description flags exploitation as difficult but not impossible. The problem is remotely launchable, and the exploit has already been publicly disclosed. EPSS data are not available, and the issue is not listed in CISA KEV. While no vendor patch is currently released, the pending pull request indicates a fix is imminent. Until that patch is applied, the vulnerability remains exploitable for attackers who can control the api_key parameter.

Generated by OpenCVE AI on October 5, 2026 at 08:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s forthcoming patch as soon as it is merged and released
  • Restrict the HTTP endpoint to trusted networks or enforce strict firewall rules
  • Use TLS to encrypt all traffic to the endpoint and disable cleartext communication
  • Disable or rotate any API keys that are exposed or potentially compromised
  • Monitor logs for abnormal api_key usage and verify the integrity of transmitted data

Generated by OpenCVE AI on October 5, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.
Title sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmission
First Time appeared Sgl-project
Sgl-project sglang
Weaknesses CWE-310
CWE-319
CPEs cpe:2.3:a:sgl-project:sglang:*:*:*:*:*:*:*:*
Vendors & Products Sgl-project
Sgl-project sglang
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sgl-project Sglang
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T06:30:14.062Z

Reserved: 2026-10-04T16:24:17.740Z

Link: CVE-2026-105245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T07:16:30.370

Modified: 2026-10-05T07:16:30.540

Link: CVE-2026-105245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:15:07Z

Weaknesses