GPU VulnDB

Database/AI/ML frameworks & serving

SGLang: server_info endpoint echoes the configured api_key back over HTTP

CVSS 2.9CVE-2026-105245AI/ML frameworks & servingcurated

Impact

The server_info handler includes the server's configured api_key in its response, so the credential that is supposed to gate the inference endpoint is served by the endpoint itself in cleartext. On a shared GPU fleet an SGLang instance is often fronted only by that static key, so anyone who can read the response can then submit arbitrary generation requests, change sampling parameters, or exhaust the GPU's KV cache and starve other work on the node. The reporter rates exploitation as high complexity and the CVSS confidentiality impact as low, which fits a credential leak that still requires the attacker to reach the HTTP port. Nothing here gives code execution or escape from the serving container.

Who can reach it

Network reach to the SGLang HTTP port. The report describes the attack as launchable remotely with no authentication, and assesses attack complexity as high.

What to do

No accepted upstream fix at the time of the record: the referenced pull request (sgl-project/sglang#30343) is still awaiting acceptance, and all versions up to 0.5.21 are described as affected. Until it lands, mitigate by keeping the SGLang port off any tenant-reachable network, terminating authentication in a gateway in front of it rather than relying on SGLang's own --api-key, and rotating that key if the endpoint has been exposed.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.