Feed/CVE-2026-15978
CVE-2026-15978HIGHCVSS 7.5

CVE-2026-15978

Published Jul 30, 2026·Updated Aug 4, 2026

NVD Description

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free