Technology · PyPI
lmdeploy (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in lmdeploy (PyPI): 0 in the last 7 days and 12 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-33625, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 12
- Critical, all time
- 4
- Exploited in the wild
- 0
About lmdeploy (PyPI)
A toolkit for compressing, deploying, and serving large language models.
Latest lmdeploy (PyPI) vulnerabilities
- CVE-2026-33625: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain…highCVSS 8.8EPSS 0.4%
- CVE-2025-66455: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior…criticalCVSS 9.8EPSS 0.7%
- LMDeploy SSRF bypass in URL validationhighCVSS 7.5
- LMDeploy SSRF bypass in URL validationlowCVSS 3.1
- CVE-2026-92983: InternLM LMDeploy memory leak in DistServe disaggregation modehighCVSS 7.5EPSS 0.7%
- CVE-2026-92971: InternLM LMDeploy assertion failure in DistServe decode migrationhighCVSS 7.5EPSS 0.7%
- CVE-2025-59953: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-76850: LMDeploy unsafe pickle deserialization in disaggregated servingcriticalCVSS 9.8EPSS 1.4%
- CVE-2026-63764: InternLM lmdeploy SSRF via HTTP redirect bypass in API servercriticalCVSS 9.3
- CVE-2025-67729: PYSEC-2026-1578 - lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()lowCVSS 3.1EPSS 0.6%
- CVE-2025-3163: PYSEC-2026-1579 - InternLM LMDeploy code injection vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2025-3162: PYSEC-2026-1577 - LMDeploy Improper Input Validation VulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2026-46517: InternLM LMDeploy remote code execution via hardcoded trust_remote_codehighCVSS 7.8EPSS 0.4%
- CVE-2026-46432: InternLM LMDeploy arbitrary code execution via hardcoded trust_remote_codehighCVSS 7.8EPSS 0.2%
- CVE-2026-33626: LMDeploy server-side request forgery in vision-language image loadinghighCVSS 7.5EPSS 1.5%
Most severe lmdeploy (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-76850: LMDeploy unsafe pickle deserialization in disaggregated servingcriticalCVSS 9.8EPSS 1.4%
- CVE-2025-59953: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior…criticalCVSS 9.8EPSS 0.8%
- CVE-2025-66455: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior…criticalCVSS 9.8EPSS 0.7%
- CVE-2026-63764: InternLM lmdeploy SSRF via HTTP redirect bypass in API servercriticalCVSS 9.3
- CVE-2026-33625: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain…highCVSS 8.8EPSS 0.4%
- CVE-2026-46517: InternLM LMDeploy remote code execution via hardcoded trust_remote_codehighCVSS 7.8EPSS 0.4%
- CVE-2026-46432: InternLM LMDeploy arbitrary code execution via hardcoded trust_remote_codehighCVSS 7.8EPSS 0.2%
- CVE-2026-33626: LMDeploy server-side request forgery in vision-language image loadinghighCVSS 7.5EPSS 1.5%
- CVE-2026-92971: InternLM LMDeploy assertion failure in DistServe decode migrationhighCVSS 7.5EPSS 0.7%
- CVE-2026-92983: InternLM LMDeploy memory leak in DistServe disaggregation modehighCVSS 7.5EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 1 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 7 | 2 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/lmdeploy.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "lmdeploy (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/lmdeploy, 26 September 2026.