lmdeploy OpenAI-Compatible API Server SSRF via Redirect-Bypassed image_url Validation
criticalZero-DayCVE-2026-63764 is a critical unauthenticated SSRF vulnerability in lmdeploy's OpenAI-compatible API server, exploitable via the image_url parameter in chat completions requests. Attackers can chain HTTP redirects to bypass initial URL validation and reach internal services or cloud instance metadata endpoints, potentially exfiltrating cloud credentials. This directly threatens organizations self-hosting lmdeploy to serve multimodal LLMs behind agent or RAG pipelines.
Updated Jul 23, 2026 · CVSS 9.3