October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

Critical LMCache Flaw Enables Unauthenticated Remote Code Execution

A critical LMCache multiprocess-mode flaw can let unauthenticated attackers execute code through unsafe ZeroMQ message deserialization. Check versions, binding, reachability, and current patch guidance.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2026-105192 is a critical remote-code-execution flaw in LMCache’s multiprocess (distributed) mode. The CVE record, published October 7, 2026, lists LMCache 0.3.9 and later as affected and names no fixed version. Its description says an unauthenticated ZeroMQ message can trigger unsafe Python pickle deserialization. Whether an attacker can reach a particular installation depends on its network binding and controls.

What CVE-2026-105192 does

JFrog assigns the vulnerability a CVSS 3.1 score of 9.8, rated Critical. The CVE record describes a flaw in the ZeroMQ request-decoding path used by LMCache’s multiprocess transport: message data is decoded with msgpack, and extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls Python’s pickle.loads before the request handler runs. Because the input is unauthenticated, a crafted message can cause code execution with the privileges of the LMCache process. CVE-2026-105192 record

LMCache documentation describes multiprocess mode as a standalone cache service that vLLM instances can contact through configurable ZeroMQ or gRPC transports; one server per node can serve multiple vLLM pods. The reported vulnerability concerns the ZeroMQ decoding path. The documentation of both transport choices does not establish that switching to gRPC is a mitigation. LMCache multiprocess documentation

Which LMCache versions and deployments are affected?

The CVE record lists versions 0.3.9 and later as affected, with no upper bound, and does not list a fixed version. This is the status in the record published October 7, 2026—not confirmation that no fix exists elsewhere. Check LMCache’s current release notes and security guidance before choosing an upgrade target.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The issue is specifically described in the context of multiprocess or distributed mode. Start by finding all LMCache installations, then establish which ones run that mode and use the affected ZeroMQ transport. The CVE’s listed version range is a reason to investigate an installation, not by itself proof that its transport is reachable from an attacker’s network.

Is the LMCache service reachable remotely?

The CVE description gives port 5555 as the default transport port and says the service binds to localhost unless an operator configures a routable address with --host. A localhost-bound socket is not ordinarily reachable through that socket from a remote network. A routable bind can make the service reachable from other hosts, depending on routing and network controls. Confirm the actual settings and reachability of each deployment rather than assuming the default.

Use this exposure checklist:

  • Record the LMCache version from the deployed environment, package metadata, lockfiles, and container images.
  • Identify whether multiprocess/distributed mode is enabled and whether the ZeroMQ transport is in use.
  • Check the effective bind address, including any --host configuration, and determine which hosts can reach the transport port.
  • Establish which operating-system user runs the LMCache process.

If a service needs cross-host access, restrict its transport path to trusted peers with deployment-appropriate network controls while consulting current project guidance. This is a risk-reduction measure based on the reported unauthenticated service, not a vendor-confirmed fix.

What could successful exploitation allow?

Code execution would run with the LMCache process’s privileges. The CVE record says official container images run as root; that claim should not be generalized to every installation, because operators may run LMCache differently. Where a reachable service ran with elevated privileges, assess potential host-level impact under your incident-response procedures. The record does not establish that any specific environment has been compromised.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The reviewed CVE record showed KEV as “No.” That field does not prove that exploitation has never happened, and the available evidence does not support claiming exploitation in the wild.

What should administrators do now?

  1. Inventory installations. Search Python environments, dependency lockfiles, container images, and deployment manifests for LMCache versions 0.3.9 and later.
  2. Map exposure. For each installation using multiprocess mode, verify the transport, bind address, port, network reachability, and process privileges.
  3. Reduce unnecessary access. If the ZeroMQ service is reachable across hosts, restrict access to required trusted peers while confirming the project’s current advice.
  4. Verify patch status. Consult LMCache’s current release notes and security channels. The October 7, 2026 CVE record did not list a fixed version, but that alone does not establish whether a fix is available from the project.
  5. Escalate suspected exposure. If an exposed instance may have received malicious input—especially one running with elevated privileges—preserve relevant logs and follow your organization’s incident-response process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep this flaw separate from the older LMCache advisory

CVE-2026-105192 is not CVE-2026-10813. The latter is a separate, low-severity local weak-hash issue affecting LMCache through version 0.4.6; it is not the unauthenticated remote-code-execution issue described here. LMCache advisory for CVE-2026-10813

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.