Database/AI/ML frameworks & serving

SGLang: server_info endpoint echoes the configured api_key back over HTTP
Impact
The server_info handler includes the server's configured api_key in its response, so the credential that is supposed to gate the inference endpoint is served by the endpoint itself in cleartext. On a shared GPU fleet an SGLang instance is often fronted only by that static key, so anyone who can read the response can then submit arbitrary generation requests, change sampling parameters, or exhaust the GPU's KV cache and starve other work on the node. The reporter rates exploitation as high complexity and the CVSS confidentiality impact as low, which fits a credential leak that still requires the attacker to reach the HTTP port. Nothing here gives code execution or escape from the serving container.
Who can reach it
Network reach to the SGLang HTTP port. The report describes the attack as launchable remotely with no authentication, and assesses attack complexity as high.
What to do
No accepted upstream fix at the time of the record: the referenced pull request (sgl-project/sglang#30343) is still awaiting acceptance, and all versions up to 0.5.21 are described as affected. Until it lands, mitigate by keeping the SGLang port off any tenant-reachable network, terminating authentication in a gateway in front of it rather than relying on SGLang's own --api-key, and rotating that key if the endpoint has been exposed.
References
Related entries
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesCVE-2025-25183 · vLLM (prefix cache hash collisions)Low
- vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' promptsCVE-2025-46570 · vLLM (prefix cache)Low
- vLLM: unvalidated bad_words token indices corrupt logits of other in-flight requestsCVE-2026-93989 · vLLM sampling parameters (bad_words token index validation)Low
- Langflow: authenticated user reaches eval() through component input options and runs code on the hostCVE-2026-101861 · Langflow schema.py (eval() on component input option values)Low
- mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference serverCVE-2026-75090 · mistral.rs GGUF tokenizer (convert_gguf_to_hf_tokenizer)Low
- Ollama: integer overflow in the GGUF v1 string reader when parsing a crafted model fileCVE-2026-86289 · Ollama GGUF decoder (readGGUFV1String in fs/ggml/gguf.go)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.