GHSA-3j7h-8qqw-4p7vHighCVSS 7.5

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe...

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

🔗 References (8)