HIGH

CVE-2026-92971

2026-09-17 CVSS v3.1
CVSS
7.5

Description

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

Weakness (CWE)

CWE-617 Reachable Assertion

EPSS Score

0.49%
Probability of exploitation in next 30 days
41.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE