What is CVE-2026-15978?
A critical model weight exfiltration vulnerability exists in SGLang when no API keys are configured. The issue exposes two endpoints, allowing a remote attacker to trigger distributed weight broadcasting via NCCL and initiate data transfer to steal all model weights. Immediate mitigation requires enforcing API key authentication.
Azərbaycanca: SGLang-də API açarları konfiqurasiya edilmədikdə, model çəkilərinin oğurlanmasına səbəb olan kritik boşluq aşkarlanıb. Bu zəiflik uzaqdan hücum edənə iki endpoint vasitəsilə NCCL protokolu ilə model çəkilərini yayımlamağa və köçürməyə imkan verir. Təhlükəsizlik üçün dərhal API açarı autentifikasiyası tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What type of data can an attacker steal by exploiting CVE-2026-15978?
An attacker can steal all model weights in SGLang. This is achieved by triggering distributed weight broadcasting via NCCL through two exposed endpoints and initiating data transfer when no API keys are configured.
What security measure should be implemented to protect against CVE-2026-15978?
API key authentication must be enforced immediately. This is the primary mitigation to address the critical vulnerability caused by unconfigured API keys in SGLang.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.