{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-3530685F",
  "slug": "cve-2026-76850-lmdeploy-pickle-rce-disaggregated-serving",
  "title": "LMDeploy pickle RCE in disaggregated serving",
  "aliases": [
    "CVE-2026-76850"
  ],
  "summary": "LMDeploy disaggregated serving is affected by unsafe pickle handling that can lead to remote code execution. Upgrade to the patched release.",
  "status": "published",
  "severity": "critical",
  "confidence": "medium",
  "uncertainty": "Confirm exact fixed LMDeploy version against the live advisory.",
  "firstObservedAt": "2026-08-19T00:00:00.000Z",
  "lastObservedAt": "2026-08-19T12:00:00.000Z",
  "publishedAt": "2026-09-20T19:55:32.083Z",
  "reviewedAt": "2026-09-20T19:55:26.102Z",
  "expiresAt": "2026-08-19T12:00:00.000Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "nvd",
      "label": "NVD CVE-2026-76850",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76850",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-08-19T12:00:00.000Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-76850-lmdeploy-pickle-rce-disaggregated-serving",
      "sourceType": "other_primary",
      "observedAt": "2026-08-19T12:00:00.000Z"
    }
  ],
  "artifacts": [],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-08-19T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-76850 LMDeploy pickle RCE disclosed.",
      "sourceIds": [
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-08-19T12:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator coverage.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Exact fixed builds must come from upstream advisory.",
    "HOL blog is operator guidance."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-76850-lmdeploy-pickle-rce-disaggregated-serving/corrections"
}
