{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/lmdeploys-openai-compatible-api-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-63764"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lmdeploy's OpenAI-compatible API server"],"_cs_severities":["critical"],"_cs_tags":["server-side-request-forgery","ssrf","vulnerability","api","cloud-security"],"_cs_type":"advisory","_cs_vendors":["lmdeploy"],"content_html":"\u003cp\u003eCVE-2026-63764 describes a critical server-side request forgery (SSRF) vulnerability within \u003ccode\u003elmdeploy\u003c/code\u003e's OpenAI-compatible API server. This flaw permits unauthenticated attackers to bypass URL safety checks and gain unauthorized access to internal services and sensitive cloud metadata. The exploitation occurs when an attacker sends a POST request to the chat completions endpoint with a specially crafted \u003ccode\u003eimage_url\u003c/code\u003e parameter. This \u003ccode\u003eimage_url\u003c/code\u003e points to an attacker-controlled server, which then issues an HTTP 302 redirect. Crucially, the \u003ccode\u003elmdeploy\u003c/code\u003e server follows this redirect to internal network addresses, such as loopback interfaces or cloud instance-metadata endpoints, without re-validating the redirected URL against its initial safety guard. This bypass allows for the exfiltration of sensitive information or interaction with internal resources, posing a significant risk to the integrity and confidentiality of the affected systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an exposed \u003ccode\u003elmdeploy\u003c/code\u003e OpenAI-compatible API server instance.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious POST request targeting the \u003ccode\u003e/v1/chat/completions\u003c/code\u003e endpoint of the \u003ccode\u003elmdeploy\u003c/code\u003e server.\u003c/li\u003e\n\u003cli\u003eThe crafted request includes an \u003ccode\u003eimage_url\u003c/code\u003e parameter set to a URL pointing to an attacker-controlled web server.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003elmdeploy\u003c/code\u003e server initiates a request to the attacker-controlled server specified in the \u003ccode\u003eimage_url\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled server responds with an HTTP 302 (Found) redirect, where the \u003ccode\u003eLocation\u003c/code\u003e header specifies an internal target, such as \u003ccode\u003ehttp://169.254.169.254/latest/meta-data/\u003c/code\u003e for AWS EC2 metadata or a local loopback address.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003elmdeploy\u003c/code\u003e server follows this 302 redirect without performing subsequent URL validation on the redirected internal target.\u003c/li\u003e\n\u003cli\u003eThe server accesses the specified internal service or cloud metadata endpoint as if it were a legitimate request originating from within the trusted network.\u003c/li\u003e\n\u003cli\u003eThe attacker receives the response from the internal service or cloud metadata, gaining unauthorized access to sensitive information or internal functionalities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63764 allows unauthenticated attackers to access internal services and cloud metadata endpoints. This can lead to the exposure of sensitive cloud credentials, internal network topology, configuration data, and potentially enable further lateral movement or privilege escalation within the compromised environment. The vulnerability carries a CVSS v3.1 base score of 9.3, indicating a critical severity and high potential for widespread damage, including severe confidentiality breaches and service disruption if internal systems are manipulated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63764 immediately by updating \u003ccode\u003elmdeploy's OpenAI-compatible API server\u003c/code\u003e to a version where this vulnerability is resolved.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect CVE-2026-63764 Exploitation Attempt - SSRF via image_url\u0026quot; to your SIEM to identify attempts at exploiting this vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unusual POST requests to the chat completions endpoint containing \u003ccode\u003eimage_url\u003c/code\u003e parameters with suspicious IP addresses or internal domain patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T21:20:46Z","date_published":"2026-07-21T21:20:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63764-lmdeploy-ssrf/","summary":"An unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-63764, exists in lmdeploy's OpenAI-compatible API server, allowing attackers to access internal services and cloud metadata by submitting a crafted image_url that redirects to internal targets.","title":"CVE-2026-63764: Server-Side Request Forgery in lmdeploy OpenAI-Compatible API Server","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63764-lmdeploy-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Lmdeploy's OpenAI-Compatible API Server","version":"https://jsonfeed.org/version/1.1"}