Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
Unpatched LMCache flaw CVE-2026-105192 lets unauthenticated attackers run code via pickle over ZeroMQ.
JFrog disclosed CVE-2026-105192, an unpatched critical flaw scored 9.8 in LMCache multiprocess mode, affecting versions 0.3.9 through 0.5.5, the 0.5.6 release candidates, and the development branch. The ZeroMQ server unpacks an unauthenticated message with Python pickle before checking its type, so a crafted message can run code as the LMCache user, which is root on official images. The server listens on localhost by default and is exposed only when bound to a routable address, including the project's example Kubernetes deployment. Separately, vLLM CVE-2026-105756, a 6.5 denial of service via a malformed cache_salt, was fixed in version 0.30.0.