Low severity3.7NVD Advisory· Published Oct 5, 2026· Updated Oct 5, 2026
CVE-2026-105245
CVE-2026-105245
Description
A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=0.5.21
Patches
Vulnerability mechanics
References
6News mentions
0No linked articles in our index yet.