InternLM's LMDeploy OpenAI-compatible API server is affected by CVE-2026-63764, a critical server-side request forgery flaw that lets unauthenticated attackers reach internal services by abusing image fetching in the /v1/chat/completions endpoint. The bug stems from validating only the initial image_url host and then following HTTP 302 redirects without re-checking whether subsequent destinations resolve to private or link-local addresses. As a result, an attacker can supply a public URL that redirects the server to targets such as 127.0.0.1 or the cloud metadata address 169.254.169.254, potentially exposing internal-only applications and cloud IAM credentials.
The vulnerability is tracked as CWE-918 and has been rated CVSS 9.2; one affected build identified in public reporting is LMDeploy git version 648df3b, while broader reporting says versions through 0.14.0 are impacted. A patch was merged to the main branch in PR #4734, but public reporting says no tagged release includes the fix yet. The issue was reportedly disclosed after a 36-day period without maintainer response following an initial report by researcher George Chen, increasing urgency for organizations running LMDeploy to review exposure and apply the upstream fix as soon as a release becomes available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Public reporting described CVE-2026-63764 as a critical SSRF in LMDeploy's OpenAI-compatible API server through version 0.14.0, exploitable via crafted image_url redirects to internal services or cloud metadata endpoints. The disclosure also stated that the issue became public after 36 days of maintainer silence.
The CVE record for CVE-2026-63764 was newly received by disclosure@vulncheck.com. The record describes an SSRF issue in InternLM's lmdeploy server caused by following redirects without re-validating private-IP protections.
A fix for the SSRF vulnerability was merged into LMDeploy's main branch in pull request #4734. The source notes that no tagged release included the patch at the time of publication.
George Chen initially reported the SSRF vulnerability in LMDeploy's OpenAI-compatible API server. The later write-up says the issue was publicly disclosed after 36 days of maintainer silence following this report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
ox.security
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.