Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. | |
| Title | sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmission | |
| First Time appeared |
Sgl-project
Sgl-project sglang |
|
| Weaknesses | CWE-310 CWE-319 |
|
| CPEs | cpe:2.3:a:sgl-project:sglang:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sgl-project
Sgl-project sglang |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T06:30:14.062Z
Reserved: 2026-10-04T16:24:17.740Z
Link: CVE-2026-105245
No data.
Status : Deferred
Published: 2026-10-05T07:16:30.370
Modified: 2026-10-05T07:16:30.540
Link: CVE-2026-105245
No data.
OpenCVE Enrichment
Updated: 2026-10-05T09:15:07Z
