AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:08.993Z and has not been modified since then. SGLang contains a model weight exfiltration vulnerability when no API keys are configured, allowing remote attackers to trigger distributed weight broadcasting and data transfer to exfiltrate model weights. Organizations using SGLang should veri [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:08.893Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This CVE-2026-15977 vulnerability in SGLang's /server_info endpoint returns sensitive information, including API keys and SSL keyfile details, when accessed with the --admin-api-key configured. Organ [truncated]