Vulnerability
Published 2026-10-07
Verified 2026-10-08

LMCache CVE-2026-105192 (CVSS 9.8, JFrog, 7 Oct): one unauthenticated ZeroMQ message to the multiprocess cache server runs code, as root on the official container images; no fixed release yet

JFrog disclosed CVE-2026-105192 on 7 October 2026, a critical flaw in LMCache, the open-source key-value cache that speeds up LLM serving engines such as vLLM. In multiprocess (distributed) mode LMCache runs as a standalone server and opens a ZeroMQ socket, port 5555 by default, so worker processes can register and share cached blocks. That socket has no authentication. One message type carries a msgpack extension that is handed to Python's pickle.loads while the server is still decoding the REGISTER_KV_CACHE arguments, before any handler or type check runs, so a single crafted message executes the sender's code as the LMCache user. JFrog says the official container images run that process as root. The 9.8 score applies when the server is bound to a routable address with --host, which is the documented multi-node setup and what LMCache's own example Kubernetes DaemonSet does (it listens on every interface); a default single-host install that stays on localhost is not reachable from other machines, and LMCache running inside a single vLLM process does not open the port at all. The decode path arrived in 0.3.9 (October 2025) and is still present in 0.5.5, the latest PyPI release, the 0.5.6 release candidates through rc3 and the dev branch as of 7 October. LMCache has not published its own advisory, and JFrog gives no way to tell whether a server has already been hit. Separately, one GitHub account opened six more LMCache security reports on 6 October alleging unauthenticated cross-tenant cache access and command-running network services; those have no CVE or maintainer confirmation. Researcher: Yuval Moravchick (JFrog). Primary: JFrog Security Research advisory JFSA-2026-001694382; wire: The Hacker News (7 Oct).

Product
LMCache (KV cache layer for vLLM and other LLM serving engines), multiprocess / distributed mode
Versions
0.3.9 through 0.5.5 (latest stable), 0.5.6rc1 to rc3, and dev branch as of 7 Oct 2026. Not reachable: default localhost bind; LMCache embedded in a single vLLM process.
CVSS
9.8 (JFrog, routable bind)
Exploited in Australia?
unknown
Patch to
No fixed version yet. Do not start the multiprocess server with a routable --host; keep port 5555 on localhost or a trusted, isolated cluster network, and change LMCache's example DaemonSet before you deploy it. A firewall narrows but does not remove the risk, because any host that can still connect can run code. Run the container as a non-root user, and watch LMCache's GitHub advisories for a release.

Primary: JFrog Security Research — LMCache unauthenticated RCE via pickle deserialization on the multiprocess ZMQ transport, CVE-2026-105192 (7 Oct 2026) · Vendor: LMCache GitHub security advisories (no advisory for CVE-2026-105192 yet) · CVE: CVE-2026-105192 · The Hacker News — Unpatched critical LMCache flaw lets unauthenticated attackers run code remotely (7 Oct 2026)

tech ai cloud