PT-2026-66563 · Nvidia+1 · Nccl+1

CVE-2026-15978

·

Published

2026-07-30

·

Updated

2026-08-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SGLang (affected versions not specified)
Description When no API keys are configured, the software exposes two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL (NVIDIA Collective Communications Library, a library for multi-GPU communication) and subsequently trigger data transfer to exfiltrate all model weights.
Recommendations Configure API keys to restrict access to the endpoints and prevent unauthorized data transfer.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15978
GHSA-CPQQ-22V3-2WFM

Affected Products

Nccl
Sglang