What is CVE-2026-63764?
LMDeploy versions up to 0.14.0 contain a server-side request forgery (SSRF) vulnerability in the media handler's _load_http_url function, as the private-IP guard fails to re-validate hosts after HTTP redirects. This allows attackers to potentially access internal network resources. Updating to the version with the fix in commit 03c3130 is required.
Azərbaycanca: LMDeploy proqramının 0.14.0 və əvvəlki versiyalarında server tərəfli sorğu saxtakarlığı (SSRF) zəifliyi aşkarlanıb. Bu zəiflik HTTP yönləndirmələrindən sonra hostları yenidən yoxlamadığı üçün təcavüzkarlara daxili şəbəkə resurslarına icazəsiz giriş imkanı verə bilər. Problemi aradan qaldırmaq üçün commit 03c3130 ilə düzəldilmiş versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What is the CVE-2026-63764 vulnerability in LMDeploy?
It is a server-side request forgery (SSRF) vulnerability in LMDeploy versions up to 0.14.0. The media handler's `_load_http_url` function fails to re-validate hosts after HTTP redirects, potentially allowing attackers to access internal network resources.
How can I fix the CVE-2026-63764 vulnerability?
To fix the issue, you need to update LMDeploy to the version that includes the patch in commit 03c3130.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.