CVE-2026-105245 | sgl-project sglang up to 0.5.21 HTTP Endpoint http_server.py server_info api_key cleartext transmission (Issue 30166)
A vulnerability, which was classified as problematic, was found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information.
This vulnerability is referenced as CVE-2026-105245. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More