Unpatched LMCache Flaw CVE-2026-105192 Allows Remote Code Execution
JFrog disclosed unpatched CVSS 9.8 LMCache flaw CVE-2026-105192, which lets attackers run code via pickle on an exposed ZeroMQ port, with a public PoC and no fix.
JFrog disclosed CVE-2026-105192, an unpatched critical flaw scored CVSS 9.8 in LMCache multiprocess mode, affecting versions 0.3.9 through 0.5.5, 0.5.6 release candidates through 0.5.6rc3, and the development branch. The ZeroMQ service, default port 5555, decodes an unauthenticated message—described as MessagePack followed by pickle.loads, including while REGISTER_KV_CACHE arguments are decoded—before type or handler checks, so one crafted DEALER message can execute code as the LMCache process. Official container images run that process as root, though Cyber Security News says this only "reportedly." The listener defaults to localhost and is exposed when bound to a routable address such as 0.0.0.0, including the project's example Kubernetes deployment; GBHackers says the 9.8 rating applies only to routable bindings and that LMCache inside a single vLLM process does not open the port. JFrog published a proof of concept on October 7, 2026, and the reports agree no patch was available. Only The Hacker News also reported vLLM CVE-2026-105756, a CVSS 6.5 denial of service from a malformed cache_salt that was fixed in vLLM 0.30.0.
- CVE-2026-105192 is an unpatched LMCache multiprocess-mode flaw rated CVSS 9.8 that allows unauthenticated remote code execution.
- Affected builds are 0.3.9 through 0.5.5, 0.5.6 release candidates through 0.5.6rc3, and the development branch.
- The ZeroMQ listener, default port 5555, deserializes unauthenticated messages with Python pickle before validation, including while decoding REGISTER_KV_CACHE arguments.
- The service binds to localhost by default and is exposed when bound to a routable address such as 0.0.0.0, including the project's example Kubernetes deployment; GBHackers says the 9.8 score applies only then.
- Official container images run the LMCache process as root; Cyber Security News qualifies this as "reportedly."
- JFrog published a proof of concept on October 7, 2026, and no patched release was available.
- LMCache inside a single vLLM process does not open the port, according to GBHackers.
- Separately, The Hacker News reported vLLM CVE-2026-105756, a CVSS 6.5 denial of service via a malformed cache_salt, fixed in vLLM 0.30.0.
Coverage timelineoldest first · each row is one article
- · 1d agoUnpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
The Hacker News· 76
Unpatched LMCache flaw CVE-2026-105192 lets unauthenticated attackers run code via pickle over ZeroMQ.
- · 12h agoCritical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available
GBHackers· 74
Unpatched LMCache flaw CVE-2026-105192 allows unauthenticated remote code execution, and JFrog published a PoC.
- · 10h agoPoC Released for Critical LMCache Flaw Enabling Unauthenticated Remote Code Execution
Cyber Security News· 67
Vulnerabilities in this storyAll →
- CVE-2026-1051929.8<1%Unauthenticated pickle RCE in LMCache distributed modepublished · LMCache (multiprocess / distributed mode) PoC
- CVE-2026-1057566.5—