CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-63764 — lmdeploy's OpenAI-compatible API server contains a server-side request forgery v...

·Source: NIST NVD

Updated:

Executive Summary

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a crafted image_url that redirects to internal targets. Attackers can send a POST request to the chat completions endpoint with an image_url pointing to an attacker-controlled server that responds wi

Analysis

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a crafted image_url that redirects to internal targets. Attackers can send a POST request to the chat completions endpoint with an image_url pointing to an attacker-controlled server that responds with an HTTP 302 redirect to internal addresses such as loopback or instance-metadata endpoints, bypassing the initial URL safety check because redirects are followed without re-validating each hop through the safety guard. CVSS Score: 9.3. Published: 2026-07-21T21:16:53.350.

Indicators of Compromise (1)

CVE (1)
CVE-2026-63764
Source Attribution

Originally published by NIST NVD on Jul 21, 2026. Verified by: NIST.

Related Threats

LOWVulnerabilityNEW

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a

Krebs on Security
MEDIUMVulnerability

Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack

Milford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email alerts, shared with DataBreaches by a town resident, reveal... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-60210 — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo...

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base

CVE-2026-60210
NIST NVD