SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.
https://kb.cert.org/vuls/id/281278
https://thoughts.apoorvdayal.com/posts/sglang-disclosures/
https://github.com/sgl-project/sglang/security/advisories/GHSA-cpqq-22v3-2wfm