CVE-2026-15978
SGLang
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.
- CVSS
- 7.5
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.31