LMDeploy Vision-Language SSRF
Unvalidated Image URL Fetching Exposes Cloud Metadata and Internal Services
CVE-2026-33626 affects LMDeploy's image-loading functionality for vision-language models. When processing OpenAI-compatible chat requests with image_url parameters, the server fetches URLs without validating destination hosts — creating a Server-Side Request Forgery primitive that grants access to cloud metadata services, internal databases, and private network topology. The vulnerability was exploited in the wild within 12 hours and 31 minutes of advisory publication.
"Attackers are increasingly weaponizing vulnerabilities in inference servers, model gateways, and agent orchestration tools within hours of advisory publication."
Vulnerability
Vision-Language Image Loader SSRF
LMDeploy's vision-language model handler processes image_url parameters from OpenAI-compatible chat requests by fetching the referenced URL server-side. No validation of destination hosts is performed, allowing an attacker to supply internal addresses — including cloud metadata endpoints, localhost services, and private network hosts — as the image source. The server then acts as an unwitting proxy, returning the fetched content to the attacker.
Attack Path
Craft Malicious Image Request
Attacker submits an OpenAI-compatible chat completion request with an image_url value pointing to an internal target — such as http://169.254.169.254/latest/meta-data/.
Any user with API access to the LMDeploy instance can trigger this — no elevated privileges required.
Server Fetches Internal URL
LMDeploy fetches the supplied URL server-side without host validation. The request originates from the model-serving host — inside the network perimeter, trusted by internal services.
The server has access to resources the attacker cannot reach directly. This is what makes SSRF on inference servers particularly dangerous in cloud environments.
Cloud Metadata / Internal Service Access
The server response — AWS IAM credentials, Redis data, MySQL responses, admin endpoint content — is returned to the attacker via the API response.
AWS metadata at 169.254.169.254 returns short-lived IAM credentials that can be used immediately for cloud-level privilege escalation.
Network Enumeration and Lateral Movement
By probing ranges of internal addresses and ports, attacker maps private network topology — discovering services, admin interfaces, and additional attack surfaces invisible from the public internet.
SSRF-based enumeration is silent from a perimeter perspective. Internal firewall rules do not apply to requests originating from within the network.
Impact
Cloud Credentials
- AWS IAM role credentials
- Instance identity documents
- Security group metadata
- Short-lived access tokens
Internal Services
- Redis cache contents
- MySQL query access
- Admin API endpoints
- Localhost-only interfaces
Network Intelligence
- Private network topology
- Internal service discovery
- Port and service enumeration
- Additional attack surface mapping
Speed of exploitation: This CVE was weaponized within 12 hours and 31 minutes of the advisory going public. AI inference servers and model gateways are now first-class targets — patch windows measured in hours, not days.
Response Checklist
Apply the patch across all environments — production, staging, and development. Given the 12-hour exploitation window observed in the wild, treat this as a same-day upgrade regardless of environment classification.
Search API request logs for image_url values containing internal IP ranges, link-local addresses (169.254.x.x), localhost, or private RFC-1918 ranges. Any hits indicate active exploitation attempts.
- 169.254.169.254 — AWS/GCP/Azure metadata service
- 10.x.x.x / 172.16–31.x.x / 192.168.x.x — RFC-1918 private ranges
- 127.0.0.1 / localhost — loopback interface
- 0.0.0.0 — wildcard address, often used in SSRF bypass attempts
Apply network-level controls preventing model-serving processes from reaching cloud metadata endpoints. On AWS, use IMDSv2 and restrict outbound access at the security group or NACLs level.
- Block egress to
169.254.169.254from inference workloads - Enforce IMDSv2 (token-required) on all AWS instances running LMDeploy
- Apply outbound firewall rules restricting RFC-1918 access from model servers
If log review reveals suspicious image_url activity before the patch was applied, assume IAM credentials reachable from the instance may be compromised. Rotate all instance-associated roles and review CloudTrail for unusual API calls.
Inference servers, model gateways, and agent orchestration tools have the same network access as any other server — and are now actively targeted. Apply the same patching cadence, access controls, and monitoring you apply to web-facing production services.
References
[1] NVD
CVE-2026-33626 — LMDeploy Vision-Language Image Loader SSRF
[2] LMDeploy Security Advisory
LMDeploy v0.7.3 release notes — SSRF fix in vision-language image URL handling, April 22, 2026