Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2240982
AlmaLinux
5967
Alpaquita
16156
Alpine
4655
Android
3677
Azure Linux
17970
BellSoft Hardened Containers
770
Bitnami
9476
Chainguard
1048381
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68939
Echo
7865
GHC
3
GIT
109017
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148242
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25463
Red Hat
23527
Rocky Linux
4342
Root
19624
RubyGems
5327
SUSE
23442
SwiftURL
60
TuxCare
9919
Ubuntu
65983
VSCode
21
Wolfi
293786
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4078
PyPI/lmdeploy
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
2 days ago
Fix available
Severity - 8.8 (High)
PYSEC-2026-4077
PyPI/lmdeploy
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
2 days ago
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-4079
PyPI/lmdeploy
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
2 days ago
Fix available
Severity - 9.8 (Critical)
GHSA-39wr-7q6h-cf68
PyPI/lmdeploy
LMDeploy has an SSRF bypass
18 Sep
Fix available
Severity - 7.5 (High)
GHSA-3hmm-rh5q-gwwr
PyPI/lmdeploy
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
18 Sep
Fix available
Severity - 8.8 (High)
GHSA-2vh9-42vm-xmv2
PyPI/lmdeploy
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
18 Sep
Fix available
Severity - 9.8 (Critical)
GHSA-5h8j-6crg-7rmw
PyPI/lmdeploy
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
16 Sep
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-2608
PyPI/lmdeploy
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
13 Jul
No fix available
Severity - 7.8 (High)
PYSEC-2026-2609
PyPI/lmdeploy
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
13 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-2607
PyPI/lmdeploy
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
13 Jul
No fix available
Severity - 7.5 (High)
PYSEC-2026-1578
PyPI/lmdeploy
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
07 Jul
Fix available
Severity - 8.8 (High)
PYSEC-2026-1579
PyPI/lmdeploy
InternLM LMDeploy code injection vulnerability
07 Jul
No fix available
Severity - 4.8 (Medium)
PYSEC-2026-1577
PyPI/lmdeploy
LMDeploy Improper Input Validation Vulnerability
07 Jul
No fix available
Severity - 4.8 (Medium)
GHSA-9xq9-36w5-q796
PyPI/lmdeploy
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
21 May
Fix available
Severity - 7.8 (High)
GHSA-m549-qq94-fvhg
PyPI/lmdeploy
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
21 May
Fix available
Severity - 7.8 (High)
GHSA-6w67-hwm5-92mq
PyPI/lmdeploy
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
21 Apr
No fix available
Severity - 7.5 (High)
Load more...
PyPI - OSV