SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63764

HIGH · CVSS 8.6 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability affects LMDeploy versions up to 0.14.0, allowing unauthenticated attackers to exploit a server-side request forgery (SSRF) flaw in the _load_http_url function. This weakness enables attackers to craft a malicious image URL that redirects to private IPs or cloud metadata endpoints, potentially exposing sensitive internal service content. Organizations using LMDeploy should prioritize patching this vulnerability to mitigate the risk of unauthorized access to their internal systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63764
Severity
HIGH
CVSS
8.6
EPSS
0.31%

Original NVD Description

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original URL without re-validating hosts after HTTP redirects. An unauthenticated attacker can submit a crafted image_url to the chat completions endpoint pointing to an attacker-controlled host that returns a redirect to a private IP or cloud-metadata endpoint, causing the server to follow the redirect and expose internal service content through the model pipeline.

Related CVEs

Other vulnerabilities affecting the same vendor(s)