Vendor
low
advisory
Denial of Service Vulnerability in InternLM LMDeploy
1 TTP 1 CVEInternLM LMDeploy version 0.17.0 and earlier is vulnerable to a denial-of-service attack due to improper session management in DistServe mode, allowing unauthenticated attackers to cause an out-of-memory failure on the prefill worker.
LMDeploy
1t
1c
medium
advisory
LMDeploy Hardcoded trust_remote_code Enables Remote Code Execution (CVE-2026-46517)
2 rules 2 TTPs 1 IOCLMDeploy <= 0.12.3 is vulnerable to remote code execution (CVE-2026-46517) because it hardcodes `trust_remote_code=True` when calling `transformers.AutoConfig.from_pretrained()`, allowing a malicious Hugging Face repository to execute arbitrary Python code when loaded without user opt-out.
transformers +1
remote code execution
supply chain
lmdeploy
2r
2t
1i