Impact
The flaw resides in sgllang’s HTTP Endpoint server_info function, where a manipulation of the api_key argument results in sensitive information being sent in cleartext. The weakness falls under the categories of transmitting data without encryption (CWE-310) and transmitting data over an insecure channel (CWE-319). As a consequence, an attacker could obtain confidential data without needing to compromise the underlying system. The impact is limited to confidentiality; there is no mention of integrity or availability damage.
Affected Systems
The vulnerability affects the sgl-project sglang component through version 0.5.21. Users deploying any of these releases—and especially those exposing the HTTP endpoint to external networks—are at risk.
Risk and Exploitability
The CVSS score of 6.3 assigns a moderate severity, while the description flags exploitation as difficult but not impossible. The problem is remotely launchable, and the exploit has already been publicly disclosed. EPSS data are not available, and the issue is not listed in CISA KEV. While no vendor patch is currently released, the pending pull request indicates a fix is imminent. Until that patch is applied, the vulnerability remains exploitable for attackers who can control the api_key parameter.
OpenCVE Enrichment