CVE-2026-105245 PUBLISHED

sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmission

Assigner: VulDB
Reserved: 04.10.2026 Published: 05.10.2026 Updated: 05.10.2026

A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.3

Product Status

Vendor sgl-project
Product sglang
Versions
  • Version 0.5.0 is affected
  • Version 0.5.1 is affected
  • Version 0.5.2 is affected
  • Version 0.5.3 is affected
  • Version 0.5.4 is affected
  • Version 0.5.5 is affected
  • Version 0.5.6 is affected
  • Version 0.5.7 is affected
  • Version 0.5.8 is affected
  • Version 0.5.9 is affected
  • Version 0.5.10 is affected
  • Version 0.5.11 is affected
  • Version 0.5.12 is affected
  • Version 0.5.13 is affected
  • Version 0.5.14 is affected
  • Version 0.5.15 is affected
  • Version 0.5.16 is affected
  • Version 0.5.17 is affected
  • Version 0.5.18 is affected
  • Version 0.5.19 is affected
  • Version 0.5.20 is affected
  • Version 0.5.21 is affected

Credits

  • geochen (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Cleartext Transmission of Sensitive Information CWE
  • Cryptographic Issues CWE