<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:07:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292289</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292289</link>
      <description>EUVD-2026-292289</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292289</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33626</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33626</link>
      <description>&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy&amp;#39;s vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources. Version 0.12.3 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy&amp;#39;s vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources. Version 0.12.3 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33626</guid>
    </item>
    <item>
      <title>GHSA-6w67-hwm5-92mq — LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6w67-hwm5-92mq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy&amp;#39;s vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- **Tested on:** main branch (2026-02-04)
- **Affected:** All versions prior to 0.12.3&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `lmdeploy/vl/utils.py` (lines 64-67)
```python
def load_image(image_url: Union[str, Image.Image]) -&amp;gt; Image.Image:
    # ...
    if image_url.startswith(&amp;#39;http&amp;#39;):
        response = requests.get(image_url, headers=headers, timeout=FETCH_TIMEOUT)
        # NO VALIDATION OF URL/IP BEFORE REQUEST
```&lt;/p&gt;
&lt;p&gt;**Also affected:** `encode_image_base64()` function (lines 26-29)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;1. No validation of URLs before fetching
2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
3. Server binds to `0.0.0.0` by default (api_server.py line 1393)
4. API keys disabled by default&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;1. LMDeploy server deployed with vision-language model
2. Attacker sends request to `/v1/chat/completions` with malicious `image_url`:
```python
POST /v1/chat/completions
{
  &amp;#34;model&amp;#34;: &amp;#34;internlm-xcomposer2&amp;#34;,
  &amp;#34;messages&amp;#34;: [{
    &amp;#34;role&amp;#34;: &amp;#34;user&amp;#34;, 
    &amp;#34;content&amp;#34;: [
      {&amp;#34;type&amp;#34;: &amp;#34;text&amp;#34;, &amp;#34;text&amp;#34;: &amp;#34;Describe this image&amp;#34;},
      {&amp;#34;type&amp;#34;: &amp;#34;image_url&amp;#34;, &amp;#34;image_url&amp;#34;: {&amp;#34;url&amp;#34;: &amp;#34;http://169.254.169.254/latest/meta-da…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy&amp;#39;s vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- **Tested on:** main branch (2026-02-04)
- **Affected:** All versions prior to 0.12.3&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `lmdeploy/vl/utils.py` (lines 64-67)
```python
def load_image(image_url: Union[str, Image.Image]) -&amp;gt; Image.Image:
    # ...
    if image_url.startswith(&amp;#39;http&amp;#39;):
        response = requests.get(image_url, headers=headers, timeout=FETCH_TIMEOUT)
        # NO VALIDATION OF URL/IP BEFORE REQUEST
```&lt;/p&gt;
&lt;p&gt;**Also affected:** `encode_image_base64()` function (lines 26-29)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;1. No validation of URLs before fetching
2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
3. Server binds to `0.0.0.0` by default (api_server.py line 1393)
4. API keys disabled by default&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;1. LMDeploy server deployed with vision-language model
2. Attacker sends request to `/v1/chat/completions` with malicious `image_url`:
```python
POST /v1/chat/completions
{
  &amp;#34;model&amp;#34;: &amp;#34;internlm-xcomposer2&amp;#34;,
  &amp;#34;messages&amp;#34;: [{
    &amp;#34;role&amp;#34;: &amp;#34;user&amp;#34;, 
    &amp;#34;content&amp;#34;: [
      {&amp;#34;type&amp;#34;: &amp;#34;text&amp;#34;, &amp;#34;text&amp;#34;: &amp;#34;Describe this image&amp;#34;},
      {&amp;#34;type&amp;#34;: &amp;#34;image_url&amp;#34;, &amp;#34;image_url&amp;#34;: {&amp;#34;url&amp;#34;: &amp;#34;http://169.254.169.254/latest/meta-da…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6w67-hwm5-92mq</guid>
    </item>
    <item>
      <title>PYSEC-2026-2607 — LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2607</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy&amp;#39;s vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- **Tested on:** main branch (2026-02-04)
- **Affected:** All versions prior to 0.12.3&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `lmdeploy/vl/utils.py` (lines 64-67)
```python
def load_image(image_url: Union[str, Image.Image]) -&amp;gt; Image.Image:
    # ...
    if image_url.startswith(&amp;#39;http&amp;#39;):
        response = requests.get(image_url, headers=headers, timeout=FETCH_TIMEOUT)
        # NO VALIDATION OF URL/IP BEFORE REQUEST
```&lt;/p&gt;
&lt;p&gt;**Also affected:** `encode_image_base64()` function (lines 26-29)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;1. No validation of URLs before fetching
2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
3. Server binds to `0.0.0.0` by default (api_server.py line 1393)
4. API keys disabled by default&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;1. LMDeploy server deployed with vision-language model
2. Attacker sends request to `/v1/chat/completions` with malicious `image_url`:
```python
POST /v1/chat/completions
{
  &amp;#34;model&amp;#34;: &amp;#34;internlm-xcomposer2&amp;#34;,
  &amp;#34;messages&amp;#34;: [{
    &amp;#34;role&amp;#34;: &amp;#34;user&amp;#34;, 
    &amp;#34;content&amp;#34;: [
      {&amp;#34;type&amp;#34;: &amp;#34;text&amp;#34;, &amp;#34;text&amp;#34;: &amp;#34;Describe this image&amp;#34;},
      {&amp;#34;type&amp;#34;: &amp;#34;image_url&amp;#34;, &amp;#34;image_url&amp;#34;: {&amp;#34;url&amp;#34;: &amp;#34;http://169.254.169.254/latest/meta-da…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lmdeploy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy&amp;#39;s vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;- **Tested on:** main branch (2026-02-04)
- **Affected:** All versions prior to 0.12.3&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `lmdeploy/vl/utils.py` (lines 64-67)
```python
def load_image(image_url: Union[str, Image.Image]) -&amp;gt; Image.Image:
    # ...
    if image_url.startswith(&amp;#39;http&amp;#39;):
        response = requests.get(image_url, headers=headers, timeout=FETCH_TIMEOUT)
        # NO VALIDATION OF URL/IP BEFORE REQUEST
```&lt;/p&gt;
&lt;p&gt;**Also affected:** `encode_image_base64()` function (lines 26-29)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;1. No validation of URLs before fetching
2. No blocklist for internal IPs (127.0.0.1, 169.254.x.x, 10.x.x.x, 192.168.x.x)
3. Server binds to `0.0.0.0` by default (api_server.py line 1393)
4. API keys disabled by default&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;1. LMDeploy server deployed with vision-language model
2. Attacker sends request to `/v1/chat/completions` with malicious `image_url`:
```python
POST /v1/chat/completions
{
  &amp;#34;model&amp;#34;: &amp;#34;internlm-xcomposer2&amp;#34;,
  &amp;#34;messages&amp;#34;: [{
    &amp;#34;role&amp;#34;: &amp;#34;user&amp;#34;, 
    &amp;#34;content&amp;#34;: [
      {&amp;#34;type&amp;#34;: &amp;#34;text&amp;#34;, &amp;#34;text&amp;#34;: &amp;#34;Describe this image&amp;#34;},
      {&amp;#34;type&amp;#34;: &amp;#34;image_url&amp;#34;, &amp;#34;image_url&amp;#34;: {&amp;#34;url&amp;#34;: &amp;#34;http://169.254.169.254/latest/meta-da…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2607</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1228 — Mozilla Thunderbird, Firefox ESR und Firefox: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1228</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird, Mozilla Firefox ESR und Mozilla Firefox ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um falsche Informationen darzustellen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Mozilla Thunderbird, Mozilla Firefox ESR und Mozilla Firefox ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um falsche Informationen darzustellen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1228</guid>
    </item>
  </channel>
</rss>
