Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
- ID
- 32837
- Status
- summarized
- Published
- 07 Oct 2026, 11:34 PM
- Fetched
- 08 Oct 2026, 12:50 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 08 Oct 2026, 12:51 AM
- Tags
- Audience
- developersai_ml_learners
What happened
JFrog disclosed CVE-2026-105192 on October 7, a 9.8-severity flaw in LMCache, the open-source cache that accelerates LLM servers such as vLLM. In LMCache's multiprocess mode the cache runs as a standalone server that LLM workers reach over an unauthenticated ZeroMQ socket; one crafted message is unpacked with pickle before the server checks the message type, so it executes attacker code as the LMCache process — which runs as root on the project's official container images. It affects versions 0.3.9 (October 2025) through 0.5.5, plus 0.5.6 release candidates and the development branch, and no fixed version exists; JFrog's advice until a patch ships is to not give the multiprocess server a routable address.
Why it matters
Exposure comes down to one startup setting: the server binds localhost by default, but LMCache's own example Kubernetes deployment starts it listening on every network interface, so teams that copied that manifest for multi-node cache sharing are running an unauthenticated root RCE right now. If you self-host vLLM or any LLM worker with LMCache's multiprocess server, check the bind address today and pin it to localhost or a private interface until a patched release lands — LMCache inside a single vLLM process does not open the port, so that setup is unaffected. There is no Malaysian-specific detail in this report, but for local teams running self-hosted inference on cloud or Kubernetes, this is an immediate config check rather than a wait-for-patch item.
Discussion angle
The insecure-by-default example: LMCache's own Kubernetes manifest binds the cache to every interface, and the process runs as root in the official images — worth walking through how many of our self-hosted inference stacks were set up by copy-pasting a vendor's sample YAML, and what a minimal safe default (localhost bind, non-root user, auth on the ZeroMQ socket) would have looked like here.