CVE-2026-15978
Awaiting Analysis Awaiting Analysis - Queue

Model Weight Exfiltration in SGLang Without API Keys

Vulnerability report for CVE-2026-15978, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: CERT/CC

Description

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SGLang has a vulnerability where model weights can be stolen if no API keys are set. Attackers can access two endpoints to trigger weight broadcasting via NCCL and force data transfer, allowing them to steal all model weights remotely.

Impact Analysis

If you use SGLang without API keys, attackers could steal your model weights, leading to loss of proprietary data, intellectual property theft, or unauthorized use of your models. This could disrupt operations or enable further attacks.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA if model weights contain sensitive or personal data. Unauthorized exfiltration may lead to compliance breaches, legal penalties, or reputational damage.

Mitigation Strategies

Configure API keys in SGLang to restrict access to sensitive endpoints. Disable NCCL-based weight broadcasting if not required. Monitor network traffic for unusual data transfers from SGLang processes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15978. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart