What is CVE-2026-15974?
SGLang's multimodal generation endpoints (/v1/chat, /v1/chat/completions) suffer from an SSRF and local file read vulnerability due to unsanitized 'image_url' parameters. This flaw allows attackers to access internal metadata, secrets, and services. Immediate input validation on URLs is required.
Azərbaycanca: SGLang multi-modal nəsil endpoint-lərində (/v1/chat, /v1/chat/completions) sanitizə olunmamış 'image_url' parametri səbəbindən SSRF və lokal fayl oxuma zəifliyi aşkarlanıb. Bu boşluq hücumçuya daxili metadata, sirrlər və xidmətlərə giriş imkanı verir. Təcili olaraq daxil olunan URL-lərin ciddi yoxlanılması təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which endpoints in SGLang are affected by the CVE-2026-15974 vulnerability?
CVE-2026-15974 affects SGLang's multimodal generation /v1/chat and /v1/chat/completions endpoints.
What resources can an attacker gain access to by exploiting CVE-2026-15974?
An attacker exploiting this SSRF and local file read vulnerability could gain access to internal metadata, secrets, and services.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.