CVE-2026-63764: SSRF in LMDeploy’s OpenAI-Compatible API Server – OX Security

AgenticGuru

OX Security has identified CVE-2026-63764, a server-side request forgery (SSRF) vulnerability in LMDeploy’s OpenAI-compatible API server. The vulnerability potentially allows attackers to make unauthorized requests from the affected server to internal or external resources. The disclosure highlights security concerns in widely-used language model deployment infrastructure.

Read Full Article →

Share This Article
Leave a Comment