Vulnerabilities & Exploits

LMCache Routable Cache Server Enables Remote Code Execution

JFrog disclosed CVE-2026-105192 in LMCache on October 7, warning that the multiprocess cache server can be reached and abused for unauthenticated remote code execution when it is bound to a routable address. The flaw affects versions 0.3.9 through 0.5.5, plus 0.5.6 release candidates and the development branch, and no fixed release exists yet.

The server accepts a network message and tries to decode a Python pickle payload before it checks whether the message is valid. Because pickle can carry executable instructions, a crafted request can make the server run the sender’s code as the LMCache process user; in the official container image, that process runs as root. LMCache’s own Kubernetes example binds the server on every interface, so deployments that copied that pattern inherit the exposure.

The practical boundary is not the cache helper itself but wherever LMCache was placed on a shared or routable network in front of LLM workers. In those setups, a single reachable port can become code execution in the serving path, and there is no patch-based cleanup path until a fixed version ships.

1 source · 9h ago

CVE-2026-105192

NVD KEV

CVSS 9.8 CRITICAL: lMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. EPSS 0.7% (50th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-10-07

Every edition of this story: LMCache Routable Cache Server Enables Remote Code Execution

More from today