CVE-2026-105245

Source
https://cve.org/CVERecord?id=CVE-2026-105245
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105245.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105245
Published
2026-10-05T06:30:14Z
Modified
2026-10-07T02:47:44Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmission
Details

A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-310",
        "CWE-319"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105245.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.5.0"
                },
                {
                    "last_affected": "0.5.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/sgl-project/sglang

Affected ranges

Type
GIT
Repo
https://github.com/sgl-project/sglang
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.5.1"
        },
        {
            "last_affected": "0.5.1"
        },
        {
            "introduced": "0.5.2"
        },
        {
            "last_affected": "0.5.2"
        },
        {
            "introduced": "0.5.3"
        },
        {
            "last_affected": "0.5.3"
        },
        {
            "introduced": "0.5.4"
        },
        {
            "last_affected": "0.5.4"
        },
        {
            "introduced": "0.5.5"
        },
        {
            "last_affected": "0.5.5"
        },
        {
            "introduced": "0.5.6"
        },
        {
            "last_affected": "0.5.6"
        },
        {
            "introduced": "0.5.7"
        },
        {
            "last_affected": "0.5.7"
        },
        {
            "introduced": "0.5.8"
        },
        {
            "last_affected": "0.5.8"
        },
        {
            "introduced": "0.5.9"
        },
        {
            "last_affected": "0.5.9"
        },
        {
            "introduced": "0.5.10"
        },
        {
            "last_affected": "0.5.10"
        },
        {
            "introduced": "0.5.11"
        },
        {
            "last_affected": "0.5.11"
        },
        {
            "introduced": "0.5.12"
        },
        {
            "last_affected": "0.5.12"
        },
        {
            "introduced": "0.5.13"
        },
        {
            "last_affected": "0.5.13"
        },
        {
            "introduced": "0.5.14"
        },
        {
            "last_affected": "0.5.14"
        },
        {
            "introduced": "0.5.15"
        },
        {
            "last_affected": "0.5.15"
        },
        {
            "introduced": "0.5.16"
        },
        {
            "last_affected": "0.5.16"
        },
        {
            "introduced": "0.5.17"
        },
        {
            "last_affected": "0.5.17"
        },
        {
            "introduced": "0.5.18"
        },
        {
            "last_affected": "0.5.18"
        },
        {
            "introduced": "0.5.19"
        },
        {
            "last_affected": "0.5.19"
        },
        {
            "introduced": "0.5.20"
        },
        {
            "last_affected": "0.5.20"
        },
        {
            "introduced": "0.5.21"
        },
        {
            "last_affected": "0.5.21"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.19
0.5.2
0.5.20
0.5.21
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
gateway-v0.*
gateway-v0.2.0
gateway-v0.2.1
gateway-v0.2.2
gateway-v0.2.3
gateway-v0.2.4
gateway-v0.3.0
gateway-v0.3.1
v0.*
v0.5.1
v0.5.1.post1
v0.5.1.post2
v0.5.1.post3
v0.5.2
v0.5.21
v0.5.2rc0
v0.5.2rc1
v0.5.2rc2
v0.5.3
v0.5.3.post1
v0.5.3.post2
v0.5.3.post3
v0.5.3rc0
v0.5.3rc1
v0.5.3rc2
v0.5.4
v0.5.4.post1
v0.5.4.post2
v0.5.4.post3
v0.5.5
v0.5.5.post1
v0.5.5.post2
v0.5.5.post3
v0.5.6
v0.5.6.post1
v0.5.6.post2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105245.json"