What is CVE-2026-15977?
This vulnerability in SGLang causes the /server_info endpoint to leak API keys and SSL keyfile information when only the --admin-api-key is configured. It leads to unauthorized exposure of sensitive credentials, requiring users to immediately apply updates or review their configurations.
Azərbaycanca: SGLang-da aşkar edilmiş bu boşluq /server_info endpoint-i vasitəsilə yalnız --admin-api-key təyin edildikdə API açarları və SSL açar faylı məlumatlarının sızmasına səbəb olur. Bu, həssas kredensialların icazəsiz əldə edilməsinə şərait yaradır, istifadəçilər dərhal müvafiq yeniləməni tətbiq etməli və ya konfiqurasiyalarını nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What information does CVE-2026-15977 in SGLang leak?
This vulnerability causes the /server_info endpoint to leak API keys and SSL keyfile information.
How to mitigate the CVE-2026-15977 vulnerability?
Users should immediately apply the relevant update or review their configurations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.