SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15978

HIGH · CVSS 7.5 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

SGLang is vulnerable to a model weight exfiltration attack when API keys are not configured, enabling remote attackers to exploit two exposed endpoints for distributed weight broadcasting via NCCL, leading to unauthorized data transfer. This vulnerability poses a significant risk as it allows attackers to exfiltrate sensitive model weights, potentially compromising the integrity of machine learning models. Organizations utilizing SGLang without proper API key configurations should prioritize addressing this vulnerability to safeguard their intellectual property and data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15978
Severity
HIGH
CVSS
7.5
EPSS
0.43%

Original NVD Description

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.

Related CVEs

Other vulnerabilities affecting the same vendor(s)