SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15974

MEDIUM · CVSS 6.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability in SGLang allows for server-side request forgery (SSRF) and local file reading through the unsanitized `image_url` parameter in the multimodal generation endpoint. This could enable attackers to access sensitive internal metadata, secrets, and services. Organizations utilizing SGLang, particularly those exposing this endpoint, should prioritize remediation to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15974
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.

Related CVEs

Other vulnerabilities affecting the same vendor(s)