Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →CVE-2026-105192 is a critical remote-code-execution flaw in LMCache’s multiprocess (distributed) mode. The CVE record, published October 7, 2026, lists LMCache 0.3.9 and later as affected and names no fixed version. Its description says an unauthenticated ZeroMQ message can trigger unsafe Python pickle deserialization. Whether an attacker can reach a particular installation depends on its network binding and controls.
What CVE-2026-105192 does
JFrog assigns the vulnerability a CVSS 3.1 score of 9.8, rated Critical. The CVE record describes a flaw in the ZeroMQ request-decoding path used by LMCache’s multiprocess transport: message data is decoded with msgpack, and extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls Python’s pickle.loads before the request handler runs. Because the input is unauthenticated, a crafted message can cause code execution with the privileges of the LMCache process. CVE-2026-105192 record
LMCache documentation describes multiprocess mode as a standalone cache service that vLLM instances can contact through configurable ZeroMQ or gRPC transports; one server per node can serve multiple vLLM pods. The reported vulnerability concerns the ZeroMQ decoding path. The documentation of both transport choices does not establish that switching to gRPC is a mitigation. LMCache multiprocess documentation
Which LMCache versions and deployments are affected?
The CVE record lists versions 0.3.9 and later as affected, with no upper bound, and does not list a fixed version. This is the status in the record published October 7, 2026—not confirmation that no fix exists elsewhere. Check LMCache’s current release notes and security guidance before choosing an upgrade target.
#1 Best Overall
The issue is specifically described in the context of multiprocess or distributed mode. Start by finding all LMCache installations, then establish which ones run that mode and use the affected ZeroMQ transport. The CVE’s listed version range is a reason to investigate an installation, not by itself proof that its transport is reachable from an attacker’s network.
Is the LMCache service reachable remotely?
The CVE description gives port 5555 as the default transport port and says the service binds to localhost unless an operator configures a routable address with --host. A localhost-bound socket is not ordinarily reachable through that socket from a remote network. A routable bind can make the service reachable from other hosts, depending on routing and network controls. Confirm the actual settings and reachability of each deployment rather than assuming the default.
Use this exposure checklist:
- Record the LMCache version from the deployed environment, package metadata, lockfiles, and container images.
- Identify whether multiprocess/distributed mode is enabled and whether the ZeroMQ transport is in use.
- Check the effective bind address, including any
--hostconfiguration, and determine which hosts can reach the transport port. - Establish which operating-system user runs the LMCache process.
If a service needs cross-host access, restrict its transport path to trusted peers with deployment-appropriate network controls while consulting current project guidance. This is a risk-reduction measure based on the reported unauthenticated service, not a vendor-confirmed fix.
What could successful exploitation allow?
Code execution would run with the LMCache process’s privileges. The CVE record says official container images run as root; that claim should not be generalized to every installation, because operators may run LMCache differently. Where a reachable service ran with elevated privileges, assess potential host-level impact under your incident-response procedures. The record does not establish that any specific environment has been compromised.
Free tools Windows power users keep installed
One-click scans. No signup required.
The reviewed CVE record showed KEV as “No.” That field does not prove that exploitation has never happened, and the available evidence does not support claiming exploitation in the wild.
What should administrators do now?
- Inventory installations. Search Python environments, dependency lockfiles, container images, and deployment manifests for LMCache versions 0.3.9 and later.
- Map exposure. For each installation using multiprocess mode, verify the transport, bind address, port, network reachability, and process privileges.
- Reduce unnecessary access. If the ZeroMQ service is reachable across hosts, restrict access to required trusted peers while confirming the project’s current advice.
- Verify patch status. Consult LMCache’s current release notes and security channels. The October 7, 2026 CVE record did not list a fixed version, but that alone does not establish whether a fix is available from the project.
- Escalate suspected exposure. If an exposed instance may have received malicious input—especially one running with elevated privileges—preserve relevant logs and follow your organization’s incident-response process.
Keep this flaw separate from the older LMCache advisory
CVE-2026-105192 is not CVE-2026-10813. The latter is a separate, low-severity local weak-hash issue affecting LMCache through version 0.4.6; it is not the unauthenticated remote-code-execution issue described here. LMCache advisory for CVE-2026-10813
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




