← Vulnerability feed

Vulnerability record · CVE-2026-15977 · published 30 July 2026

CVE-2026-15977: Lmsys sglang insufficiently protected credentials vulnerability

Lmsys · Sglang

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

7.5 CVSS 3.1 High EPSS 0.41% · top 66.9% CWE-522 · Insufficiently protected credentials
7.5CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
4 Aug 2026Last modified by NVD

Description

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-15977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-15969Lmsys sglang deserialization of untrusted data vulnerabilitySGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…EPSS 1.0%9.8CVE-2026-15971Lmsys sglang vulnerabilitySGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena…EPSS 0.73%9.8CVE-2026-15976Lmsys sglang deserialization of untrusted data vulnerabilitySGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…EPSS 0.60%9.8CVE-2026-7301Lmsys sglang deserialization of untrusted data vulnerabilitySGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming…EPSS 0.60%9.8CVE-2026-7304Lmsys sglang deserialization of untrusted data vulnerabilitySGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl…EPSS 0.88%9.8CVE-2026-5760Lmsys sglang code injection vulnerabilitySGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load…EPSS 1.1%9.8CVE-2026-3059Lmsys sglang deserialization of untrusted data vulnerabilitySGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat…EPSS 1.3%9.8CVE-2026-3060Lmsys sglang deserialization of untrusted data vulnerabilitySGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-15977), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.