CVE-2026-92971: Internlm Lmdeploy

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

Affected products

  • Internlm Lmdeploy: up to and including 0.17.0

Published 2026-09-17. Last modified 2026-09-22.