Active Exploitation
#threatreport #LowCompleteness
CVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours | 22-04-2026
Source: https://webflow.sysdig.com/blog/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours
Key details below ↓
🎯Victims: Lmdeploy, Artificial intelligence infrastructure, Inference servers, Model gateways, Agent orchestration tools
🔓CVEs: CVE-2026-33626 \[[Vulners](https://vulners.com/cve/CVE-2026-33626)]
- CVSS V3.1: *7.5*,
- Vulners: Exploitation: True
Soft:
- internlm lmdeploy (<0.12.3)
📚TTPs:
⚔️Tactics: 1
🛠️Technics: 0
🤖LLM extracted TTPs:`
T1016.001, T1046, T1190, T1499.004, T1552.005
🧨IOCs:
- IP: 3
- Domain: 1
- File: 1
- Url: 1
💽Software: Redis, MySQL, OpenAI, Ollama, Docker
🔠Functions: _is_safe_url
#threatreport:
On April 21, 2026, a Server-Side Request Forgery (SSRF) vulnerability, registered as CVE-2026-33626, was identified in LMDeploy, a toolkit designed for serving vision-language and text large language models created by Shanghai AI Laboratory. The vulnerability stems from a lack of hostname resolution checks, the absence of a private-network blocklist, and insufficient protection for link-local addresses. Consequently, any URL with an http:// or https:// scheme could be fetched and relayed by the server, enabling potential attackers to exploit this weakness.
Just over 12 hours after the vulnerability was disclosed, attempts to exploit it were observed. The Sysdig Threat Research Team noted that the attacker utilized the vision-language image loader to conduct port scans on the internal network. This revealed significant targets, including the AWS Instance Metadata Service (IMDS), Redis, MySQL databases, additional HTTP administrative interfaces, and out-of-band DNS exfiltration points. The exploitation was characterized by a rapid, eight-minute session where the first request directly targeted the AWS IMDS followed by probing the Redis loopback port.
The attacker's strategy showcased how the SSRF could be weaponized within a cloud infrastructure context, taking advantage of common ports such as 6379 for Redis, known for being targeted following IMDS access. Following this reconnaissance, further attempts were made to establish egress points using an out-of-band DNS callback to exfiltrate data.
The implications of CVE-2026-33626 are profound, particularly as it highlights a troubling trend: critical vulnerabilities in AI-related infrastructure are increasingly being exploited within hours post-disclosure. Attackers can leverage these vulnerabilities to gain access to sensitive resources, including IAM credentials and cloud metadata. Such access can lead to severe ramifications, including compromising cloud accounts and disrupting service via denials of service on inference processes.
Defensive strategies are vital considering this pattern of rapid exploitation. Application layer protections should include logging and alerting for requests made to internal network ranges or well-known service ports. Moreover, at the host layer, runtime detection should focus on identifying outbound connections from inference processes, particularly to cloud metadata endpoints. The swift identification of exploitation attempts underscores the need for proactive security measures, distancing from reliance on delayed patches or scans to ensure the integrity of AI-serving frameworks in the face of emerging threats.
Post summary
Within 12 hours of discovery, attackers leveraged the SSRF flaw in LMDeploy to access cloud metadata and internal services; no PoC, patch, or workaround is provided.