Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33626

70
FAUCET Score

OVERVIEW CVE-2026-33626 is a Server-Side Request Forgery (SSRF) vulnerability affecting LMDeploy, a toolkit for compressing, deploying, and serving large language models. The flaw exists in the vision-language module's load_image() function, which fails to validate internal and private IP addresses when fetching URLs. This allows unauthenticated attackers to make arbitrary network requests to cloud metadata services and internal resources. LMDeploy versions prior to 0.12.3 are affected; version 0.12.3 contains the patch. SEVERITY The vulnerability carries a HIGH severity rating with CVSS 3.1 score of 7.5, reflecting its network-accessible attack vector requiring no special privileges or user interaction. The attack complexity is low, meaning exploitation is straightforward. The potential impact is significant, enabling attackers to access sensitive cloud metadata and internal network resources, resulting in unauthorized information disclosure. No integrity or availability impact is documented. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The EPSS score of 0.000310 indicates minimal probability of exploitation within the next 30 days. Community attention remains inactive based on available threat intelligence data. Organizations should prioritize updating to version 0.12.3 to mitigate exposure, though immediate exploitation risk appears low.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.12.3CPE matchmatch criteria
cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
45.25%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-33626 · Apr 23, 2026
This CVE's current EPSS score of 0.4525 is in the 98th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-6w67-hwm5-92mqhigh

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

Apr 21, 2026

References

github.com / InternLM/lmdeploy/commit/71d64a339edb901e9005358e0633fbbab367d626
Patch
github.com / InternLM/lmdeploy/pull/4447
Issue TrackingPatch
github.com / InternLM/lmdeploy/releases/tag/v0.12.3
Release Notes
github.com / InternLM/lmdeploy/security/advisories/GHSA-6w67-hwm5-92mq
ExploitMitigationVendor Advisory