Vulnerability record · CVE-2026-33626 · published 20 April 2026
CVE-2026-33626: LMDeploy vision-language load_image() SSRF via unvalidated URLs
IInternlm · Lmdeploy
LMDeploy versions before 0.12.3 have a server-side request forgery flaw in the vision-language module. The load_image() function in lmdeploy/vl/utils.py fetches arbitrary URLs without validating internal or private IP addresses, so a request can be pointed at cloud metadata services or internal network resources. Version 0.12.3 patches the issue.
Description
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources. Version 0.12.3 patches the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityNetwork-reachable, unauthenticated SSRF with high confidentiality impact and a high EPSS percentile, though no KEV listing or known ransomware use.
What it is
LMDeploy versions before 0.12.3 have a server-side request forgery flaw in the vision-language module. The load_image() function in lmdeploy/vl/utils.py fetches arbitrary URLs without validating internal or private IP addresses, so a request can be pointed at cloud metadata services or internal network resources. Version 0.12.3 patches the issue.
Impact
An attacker can make the LMDeploy server issue requests to internal addresses, potentially reading cloud instance metadata credentials and reaching sensitive internal services. The CVSS vector shows high confidentiality impact with no integrity or availability effect.
Attack surface
Reachable over the network through the vision-language image loading path, with no authentication and no user interaction required per the CVSS vector (AV:N/PR:N/UI:N). Any interface that accepts an image URL and passes it to load_image() is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.4525 (98.7th percentile), indicating elevated predicted exploitation activity. The vendor advisory reference is tagged Exploit, so public exploit detail exists.
What to do
- Upgrade LMDeploy to 0.12.3 or later, which patches the flaw.
- If upgrade is not immediate, block outbound requests from LMDeploy hosts to private, link-local and cloud metadata ranges (169.254.169.254, RFC1918, loopback).
- Restrict the vision-language endpoint to trusted clients and require authentication where possible.
- Apply egress filtering and network segmentation so the LMDeploy service cannot reach internal management or metadata services.
- Review the vendor advisory GHSA-6w67-hwm5-92mq for any additional mitigations.
Detection
- Monitor LMDeploy host outbound connections to 169.254.169.254 and RFC1918 addresses for unexpected image fetches.
- Log and alert on load_image() or vision-language requests containing URLs with internal, loopback or metadata hostnames.
- Watch for repeated or anomalous HTTP requests originating from the LMDeploy process to non-public destinations.
- Correlate LMDeploy access logs with egress firewall denials to spot SSRF probing attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/InternLM/lmdeploy/commit/71d64a339edb901e9005358e0633fbbab367d626 | Patch |
| https://github.com/InternLM/lmdeploy/pull/4447 | Issue TrackingPatch |
| https://github.com/InternLM/lmdeploy/releases/tag/v0.12.3 | Release Notes |
| https://github.com/InternLM/lmdeploy/security/advisories/GHSA-6w67-hwm5-92mq | ExploitMitigationVendor Advisory |
| https://github.com/InternLM/lmdeploy/security/advisories/GHSA-6w67-hwm5-92mq | ExploitMitigationVendor Advisory |
Track CVE-2026-33626 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-33626), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.