<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:32:10.558844+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292289</id>
    <title>EUVD-2026-292289</title>
    <updated>2026-10-02T16:32:10.622499+00:00</updated>
    <content>EUVD-2026-292289</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33626</id>
    <title>fkie_cve-2026-33626</title>
    <updated>2026-10-02T16:32:10.622536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources. Version 0.12.3 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6w67-hwm5-92mq</id>
    <title>GHSA-6w67-hwm5-92mq — LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading</title>
    <updated>2026-10-02T16:32:10.622571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lmdeploy</p>
<p>## Summary</p>
<p>A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.</p>
<p>## Affected Versions</p>
<p>- **Tested on:** main branch (2026-02-04)
- **Affected:** All versions prior to 0.12.3</p>
<p>## Vulnerable Code</p>
<p>**File:** `lmdeploy/vl/utils.py` (lines 64-67)
```python
def load_image(image_url: Union[str, Image.Image]) -&gt; Image.Image:
    # ...
    if image_url.startswith('http'):
        response = requests.get(image_url, headers=headers, timeout=FETCH_TIMEOUT)
        # NO VALIDATION OF URL/IP BEFORE REQUEST
```</p>
<p>**Also affected:** `encode_image_base64()` function (lines 26-29)</p>
<p>## Root Cause</p>
<p>1. No validation of URLs before fetching
2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
3. Server binds to `0.0.0.0` by default (api_server.py line 1393)
4. API keys disabled by default</p>
<p>## Attack Scenario</p>
<p>1. LMDeploy server deployed with vision-language model
2. Attacker sends request to `/v1/chat/completions` with malicious `image_url`:
```python
POST /v1/chat/completions
{
  "model": "internlm-xcomposer2",
  "messages": [{
    "role": "user", 
    "content": [
      {"type": "text", "text": "Describe this image"},
      {"type": "image_url", "image_url": {"url": "http://169.254.169.254/latest/meta-da…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6w67-hwm5-92mq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2607</id>
    <title>PYSEC-2026-2607 — LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading</title>
    <updated>2026-10-02T16:32:10.622634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lmdeploy</p>
<p>## Summary</p>
<p>A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.</p>
<p>## Affected Versions</p>
<p>- **Tested on:** main branch (2026-02-04)
- **Affected:** All versions prior to 0.12.3</p>
<p>## Vulnerable Code</p>
<p>**File:** `lmdeploy/vl/utils.py` (lines 64-67)
```python
def load_image(image_url: Union[str, Image.Image]) -&gt; Image.Image:
    # ...
    if image_url.startswith('http'):
        response = requests.get(image_url, headers=headers, timeout=FETCH_TIMEOUT)
        # NO VALIDATION OF URL/IP BEFORE REQUEST
```</p>
<p>**Also affected:** `encode_image_base64()` function (lines 26-29)</p>
<p>## Root Cause</p>
<p>1. No validation of URLs before fetching
2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
3. Server binds to `0.0.0.0` by default (api_server.py line 1393)
4. API keys disabled by default</p>
<p>## Attack Scenario</p>
<p>1. LMDeploy server deployed with vision-language model
2. Attacker sends request to `/v1/chat/completions` with malicious `image_url`:
```python
POST /v1/chat/completions
{
  "model": "internlm-xcomposer2",
  "messages": [{
    "role": "user", 
    "content": [
      {"type": "text", "text": "Describe this image"},
      {"type": "image_url", "image_url": {"url": "http://169.254.169.254/latest/meta-da…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1228</id>
    <title>WID-SEC-W-2026-1228 — Mozilla Thunderbird, Firefox ESR und Firefox: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:32:10.622687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird, Mozilla Firefox ESR und Mozilla Firefox ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um falsche Informationen darzustellen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1228"/>
  </entry>
</feed>
