CVE-2026-15974 | sgl-project SGLang up to 0.5.15 Multimodal Generation Endpoint /v1/chat/completions image_url server-side request forgery

SecurityVulns

A vulnerability classified as critical was found in sgl-project SGLang up to 0.5.15. Affected by this issue is some unknown functionality of the file /v1/chat/completions of the component Multimodal Generation Endpoint. Such manipulation of the argument image_url leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2026-15974. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More