Ghostwire

CVE-2026-15974: SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to...

MEDIUM CVSS 0.0

Published: July 30, 2026 | Last Modified: July 30, 2026

Description

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References