CVE-2026-15974: SSRF
Published Jul 30, 2026
·Updated
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized imageurl, allowing access to internal metadata, secrets, and services.
Affected Software
2 affected components
SGLang SGLang
Lmsys Sglang<=0.5.15
Event History
Jul 30, 2026
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15974?
CVE-2026-15974 has a risk score of 76.
2
How do I fix CVE-2026-15974?
To fix CVE-2026-15974, ensure that the image_url input is properly sanitized to prevent SSRF and local file read vulnerabilities.
3
What systems are affected by CVE-2026-15974?
CVE-2026-15974 affects the SGLang software, specifically in the multimodal generation endpoint /v1/chat/completions.
4
What types of attacks can be performed due to CVE-2026-15974?
CVE-2026-15974 allows attackers to access internal metadata, secrets, and services through SSRF and local file read exploits.
5
When was CVE-2026-15974 published?
CVE-2026-15974 was published on July 30, 2026.