Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available
Unpatched LMCache flaw CVE-2026-105192 allows unauthenticated remote code execution, and JFrog published a PoC.
JFrog disclosed CVE-2026-105192, a CVSS 9.8 LMCache flaw that lets unauthenticated attackers execute code on reachable multiprocess deployments by sending a malicious pickle object over an unauthenticated ZeroMQ transport. Deserialization happens while REGISTER_KV_CACHE arguments are decoded, before handler checks. The bug has been present since version 0.3.9 and remained unfixed through 0.5.5, candidates up to 0.5.6rc3, and the development branch when JFrog published a PoC on October 7, 2026. The 9.8 rating applies only when operators bind a routable address; the default is localhost, and LMCache inside a single vLLM process does not open the port.
- Pickle deserialization on LMCache's ZeroMQ port yields unauthenticated RCE.
- JFrog's October 7 PoC works; no patched release was available.
- CVSS 9.8 applies only to routable host bindings, not localhost.
- Vulnerable from 0.3.9 through 0.5.5 and 0.5.6 release candidates.
- Official containers run the process as root inside the container.
Vulnerabilities mentionedAll →
- CVE-2026-1051929.8<1%Unauthenticated pickle RCE in LMCache distributed modepublished · LMCache (multiprocess / distributed mode) PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-105192 | Unauthenticated pickle RCE in LMCache distributed mode |
Full article534 words · extracted from gbhackers.com · click to collapse
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python pickle deserialization.
This flaw is tracked as CVE-2026-105192 and has a CVSS score of 9.8. JFrog published an advisory and a public proof-of-concept exploit on October 7, 2026, stating that no fixed release was available as of that date.
Yuval Moravchick of the JFrog Security Research Team discovered the vulnerability, and it is documented under advisory JFSA-2026-001694382.
The vulnerable decoding path first appeared in version 0.3.9 and remains present in version 0.5.5, as well as in all release candidates up to 0.5.6rc3 and the development branch reviewed on October 7.
LMCache RCE Vulnerability
LMCache’s multiprocess mode, also known as distributed mode, opens a ZeroMQ ROUTER socket that allows worker processes to register and share key-value cache blocks.
Although this transport is designed for sibling LMCache processes, it lacks authentication (e.g., CURVE, ZAP, or password protection), leaving reachable instances vulnerable to untrusted messages.
By default, this transport uses localhost. Operators can enable connectivity between nodes by configuring a routable address using the `–host` option.
JFrog emphasizes that the severe 9.8 score applies only to this network-reachable configuration, not to the default single-host deployment, which is inaccessible from other machines. LMCache running solely within a vLLM process does not open the affected port.
Incoming messages use MessagePack, with extension code 1 associated with DeviceIPCWrapper. During decoding, the extension hook in `lmcache/v1/multiprocess/custom_types.py` forwards the embedded data to `DeviceIPCWrapper.Deserialize` in `lmcache/v1/platform/base/ipc_wrapper.py`. This function invokes `pickle.loads`, allowing attacker-controlled serialized objects to trigger code execution.
Importantly, deserialization occurs while the server processes REGISTER_KV_CACHE arguments, before the request handler is executed. As a result, any argument checks or handler errors that follow cannot prevent code that has already been executed during decoding.
JFrog’s public demonstration sends a crafted multipart message through a ZeroMQ DEALER socket to the transport’s default port, 5555. The cache payload includes a MessagePack extension containing a malicious pickle object that executes an operating system command during reconstruction.
The demonstration writes the output of the `id` command to `/tmp/zmq_pwn`, confirming execution under the LMCache process account. Official container images run this process as root, confirming root execution inside the container, rather than demonstrating an escape to the underlying host.
After execution, the server logs a type error because the handler receives the command’s return value instead of the expected wrapper object. This error occurs too late to prevent exploitation.
JFrog recommends replacing pickle-based network deserialization with a safe serialization format and authenticating the ZeroMQ transport using methods like CURVE or per-message HMAC verification. Routable binding should be disallowed unless authentication is configured.
Until these changes are implemented, operators should avoid using routable `–host` settings, keep localhost binding whenever possible, and restrict required cluster access with firewall rules. While network isolation can limit exposure, it does not fix the flaw; any system that can connect to the vulnerable transport can still execute code with the privileges of the LMCache process.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.