logo

New LMDeploy Vulnerability Exploited in the Wild Just 12 Hours After Public Advisory

ID: 525285a2-a73e-56e1-8a2f-0c6ef3b3c1bc

STIX ID: report--525285a2-a73e-56e1-8a2f-0c6ef3b3c1bc

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: AnuPriya

...
...

A Server-Side Request Forgery (SSRF) vulnerability in LMDeploy (CVE-2026-33626) was weaponized in the wild within 12 hours and 31 minutes of disclosure; attackers used the vulnerable vision-image loader to probe AWS Instance Metadata (169.254.169.254), localhost services (Redis 6379, MySQL 3306), and an unauthenticated /distserve admin endpoint, and confirmed blind SSRF via an out-of-band callback domain. The patched LMDeploy v0.12.3 blocks link-local, loopback, and private ranges; operators are urged to upgrade, enforce IMDSv2, and restrict outbound egress for inference nodes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.