CVE-2026-76850 | InternLM lmdeploy up to 0.15.x Disaggregated Serving engine_conn.py recv_pyobj deserialization

SecurityVulns

A vulnerability classified as critical has been found in InternLM lmdeploy up to 0.15.x. The affected element is the function recv_pyobj of the file lmdeploy/pytorch/disagg/conn/engine_conn.py of the component Disaggregated Serving. This manipulation causes deserialization.

This vulnerability appears as CVE-2026-76850. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More