Signal is active with 14 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
‼️ UNPATCHED >> A single network message can trigger code execution on an LMCache multiprocess server without authentication when the server is bound to a routable address.
CVE-2026-105192 affects LMCache 0.3.9 through 0.5.5, plus 0.5.6 release candidates.
Details → https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Register a cache block. The server unpickles it. You're root.
🚨 Unauthenticated RCE in LMCache, found by JFrog Research 🚨
CVE-2026-105192 https://t.co/vBxcpWrnUN
⚠️ UNPATCHED CRITICAL LMCACHE FLAW LETS UNAUTHENTICATED ATTACKERS RUN CODE ON LLM CACHE SERVERS (CVE-2026-105192, CVSS 9.8)
JFrog Security Research has disclosed an unauthenticated remote code execution flaw in LMCache, a KV-cache layer for LLM inference used with engines such as vLLM. No fixed release is available yet.
• Where: multiprocess (distributed) mode opens a ZeroMQ socket, port 5555 by default, with no authentication
• How: one message type is decoded with Python pickle before the request handler runs, so a single crafted message runs code as the LMCache process user, which is root in the official container images
• Affected: v0.3.9 through v0.5.5 (the latest PyPI release), plus the v0.5.6 release candidates through rc3 and the dev branch
• Exposure: the socket binds to localhost by default. The 9.8 score applies when an operator binds it to a routable address, the documented multi-node setup. LMCache running only inside a vLLM process does not open this port
⚠️ Analyst Note:
No exploitation in the wild has been reported, and the flaw is not in CISA KEV. Until a patch ships, JFrog advises keeping the multiprocess port on localhost or a trusted cluster network. A firewall narrows who can reach it, but any host that can still connect can run code.
Source:
https://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/
#DDW#DarkWeb#CyberSecurity#LMCache#vLLM#CVE#AISecurity
LMCache (cache p/ servidores LLM como vLLM) tem RCE sem autenticação, CVE-2026-105192 (9.8), nas versões 0.3.9 a 0.5.5. Sem correção. Só afeta o modo multiprocess em endereço roteável. Mitigação: manter na localhost e restringir a porta.
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Critical LMCache flaw CVE-2026-105192 allows unauthenticated code execution on reachable multiprocess servers. No patch is available. Restrict ZeroMQ access now and contact FORTBRIDGE for an assessment. #LMCache#CyberSecurity https://t.co/mdivpYzaNC
1/5 One unauthenticated network message can become code execution on an LMCache server.
CVE-2026-105192 affects the multiprocess mode used to share LLM KV-cache data between workers.
CVSS 9.8. No fixed release is available. 🧵 https://t.co/Ifv7iEUzNz
Run self-hosted LLM inference? Check what's listening on port 5555. An unpatched flaw in LMCache — the KV-cache behind vLLM — lets one unauthenticated packet run code as root on your cache server. CVE-2026-105192, CVSS 9.8, no fix yet.
https://zerohunt.ai/blog/lmcache-cve-2026-105192-unauthenticated-rce/
ثغرة حرجة غير مُصلحة في LMCache تسمح بتنفيذ التعليمات برسالة شبكة واحدة دون مصادقة.
تُعرف بـ CVE-2026-105192 وتؤثر على LMCache 0.3.9 حتى 0.5.5 والإصدارات التجريبية من 0.5.6.
أي مطور يستخدم LMCache على خادم متعدد العمليات مربوط بعنوان قابل للتوجيه معرض للخطر.
Critical LMCache vulnerability: inference optimization introduces another security boundary
JFrog disclosed CVE-2026-105192, an unauthenticated remote-code-execution vulnerability in LMCache’s multiprocess transport.
Severity: CVSS 9.8.
Affected releases include LMCache 0.3.9 through 0.5.5, with vulnerable code also identified in 0.5.6 release candidates.
The vulnerability involves unsafe deserialization of messages received through an unauthenticated ZeroMQ interface.
The critical qualification: remotely reachable exposure requires the multiprocess service to be bound to a routable address. Default localhost-only deployments are not remotely exposed in the same way.
No patched release was available at disclosure. JFrog recommends restricting access to the multiprocess interface until a fix is released.
4/ Oktober 2026 veröffentlichte LMCache-Schwachstelle CVE-2026-105192 betrifft genau diese Grenze. Sie ist kein Prompt-Injection-Angriff und kein Fehlverhalten eines Modells.
Attackers exploited CVE-2026-105192 in LMCache to achieve remote code execution via unauthenticated pickle deserialization, then moved laterally across trusted AI cluster networks. Runtime segmentation helps contain post-compromise activity in multi-tenant LLM infrastructure. #CloudSecurity
🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/lmcache-critical-vulnerability-cve-2026-105192-remote-code-execution
LMCache, the KV-cache layer under a lot of vLLM setups, has an unauthenticated RCE and no patch (CVE-2026-105192, 9.8).
One ZeroMQ message to port 5555 and it runs pickle.loads before any handler checks anything. Official images run as root.
Only multiprocess mode on a routable address. Keep it on localhost or firewall it hard.
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
⚠️ LMCache : CVE-2026-105192 (CVSS 9,8) permet une RCE sans authentification en mode multiprocess si le port ZeroMQ est routable. Aucun correctif publié, pas d’exploitation observée. Restreignez le port 5555 à localhost ou firewall. #Cyber#IA