CVE-2026-15978: High severity SGLang vulnerability
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15978?
CVE-2026-15978 has a risk score of 83, indicating a high severity vulnerability.
What does CVE-2026-15978 exploit?
CVE-2026-15978 exploits a model weight exfiltration vulnerability due to the absence of API keys in SGLang.
How can I mitigate CVE-2026-15978?
To mitigate CVE-2026-15978, ensure that API keys are configured to prevent unauthorized access to the exposed endpoints.
What are the consequences of CVE-2026-15978?
The consequences of CVE-2026-15978 include the potential for remote attackers to exfiltrate all model weights from the SGLang application.
When was CVE-2026-15978 published?
CVE-2026-15978 was published on July 30, 2026.