CVE-2026-92971
InternLM LMDeploy through 0.17.0 Assertion Denial of Service
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.
| CWE | CWE-617 |
| Vendor | internlm |
| Product | lmdeploy |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for internlm lmdeploy
Be the first to know when new high vulnerabilities affecting internlm lmdeploy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
InternLM / lmdeploy
0 โค 0.17.0
References
github.com: https://github.com/InternLM/lmdeploy/issues/4965 github.com: https://github.com/InternLM/lmdeploy/blob/v0.17.0/lmdeploy/pytorch/engine/engine_loop.py#L560-L564 github.com: https://github.com/InternLM/lmdeploy/blob/v0.17.0/lmdeploy/serve/openai/endpoints/completions.py#L130-L136 github.com: https://github.com/InternLM/lmdeploy/blob/v0.17.0/lmdeploy/pytorch/utils.py#L187-L214 github.com: https://github.com/InternLM/lmdeploy vulncheck.com: https://www.vulncheck.com/advisories/internlm-lmdeploy-through-0.17.0-assertion-denial-of-service
Credits
Jiapeng Li Jiajia Liu