← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 30, 2026 · 18:09via CERT/CC Vulnerability Notes

VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure

Brief

Overview

Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authentication in most cases, and some vulnerabilities require only network access with no API keys or user credentials.

At the time of publication, no patches are available from the project maintainers, and coordination attempts have been unsuccessful.

Description

SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs.

Read more on CERT/CC Vulnerability Notes