Sceawere

Vulnerability Detail

CVE-2026-105245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SGLang Sensitive Information Exposure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
11h ago
Vendor
sgl-project
Product
sglang
Attack Type
Cleartext Transmission of Sensitive Information
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-05T07:16:30.370Z",
  "pubdate": "2026-10-05T07:16:30.370Z",
  "executiveSummary": "A sensitive information disclosure vulnerability exists in the sgl-project sglang library up to version 0.5.21. The vulnerability resides within the server_info function of the HTTP endpoint, specifically concerning the mishandling of the api_key parameter.\nThis flaw facilitates the cleartext transmission of sensitive authentication credentials, potentially allowing unauthorized parties to intercept credentials during communication. The impact is significant, as it compromises the confidentiality of administrative or user API keys used for securing the sglang server infrastructure.\nThe attack is classified as remotely exploitable, though the inherent complexity and difficulty of the exploitation process are noted. Despite the difficulty, public disclosure of the exploit increases the risk to affected deployments. Users are cautioned that until the pending fix is merged, exposure of the API key can lead to unauthorized access or control over the server environment.\nThe vulnerability highlights a failure in secure input handling and data transmission protocols within the application's internal API management logic.",
  "technicalDetails": "The vulnerability is located within python/sglang/srt/entrypoints/http_server.py in the server_info function. The root cause is improper handling of the api_key argument during HTTP request processing, where the system fails to sanitize or protect the parameter from being exposed in cleartext logs, responses, or transmission headers.\nIn the context of the HTTP Endpoint, the server_info function is designed to return metadata about the running instance. Due to logic flaws in how the request parameters are parsed and subsequently processed or returned, the sensitive api_key provided during the interaction is not properly masked or redacted. When an attacker submits a crafted request to this endpoint, they may trigger a response or side effect that includes the API key in the communication stream.\nThe attack flow involves a remote actor sending an HTTP request to the vulnerable endpoint. By manipulating the api_key argument, the attacker interacts with the internal server logic that inadvertently leaks the credential. Since this happens over standard HTTP/HTTPS protocols, if the communication channel is monitored or if the application logs these parameters without adequate security controls, the credential is exposed.\nThe complexity of the exploitation is assessed as high, suggesting that the attacker must have specific knowledge of the internal state or the precise request formatting required to force the server to reveal the information. However, since the vulnerability resides in a core HTTP endpoint, it does not require prior authentication to reach the vulnerable function, lowering the barrier for entry if the attacker can successfully navigate the required request structure.\nThe exposure of the api_key is critical as this credential likely provides authorized access to the sglang runtime. Once obtained, a malicious actor could theoretically perform unauthorized operations against the sglang instance, potentially leading to remote command execution, data exfiltration, or service disruption depending on the permissions associated with the compromised key. The current lack of a merged patch in the upstream repository means that all versions up to 0.5.21 remain vulnerable to this information disclosure vector."
}
CVE-2026-105245: SGLang Sensitive Information Exposure (LOW Severity, CVSS: 3.7) | Sceawere