OVERVIEW CVE-2026-33626 is a Server-Side Request Forgery (SSRF) vulnerability affecting LMDeploy, a toolkit for compressing, deploying, and serving large language models. The flaw exists in the vision-language module's load_image() function, which fails to validate internal and private IP addresses when fetching URLs. This allows unauthenticated attackers to make arbitrary network requests to cloud metadata services and internal resources. LMDeploy versions prior to 0.12.3 are affected; version 0.12.3 contains the patch. SEVERITY The vulnerability carries a HIGH severity rating with CVSS 3.1 score of 7.5, reflecting its network-accessible attack vector requiring no special privileges or user interaction. The attack complexity is low, meaning exploitation is straightforward. The potential impact is significant, enabling attackers to access sensitive cloud metadata and internal network resources, resulting in unauthorized information disclosure. No integrity or availability impact is documented. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The EPSS score of 0.000310 indicates minimal probability of exploitation within the next 30 days. Community attention remains inactive based on available threat intelligence data. Organizations should prioritize updating to version 0.12.3 to mitigate exposure, though immediate exploitation risk appears low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.3CPE matchmatch criteria | cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.