LMCache unauthenticated remote code execution (CVE-2026-105192)
Vulnerability
Summary
Hide ▲
Show ▼
LMCache has a critical unauthenticated remote code execution flaw, CVE-2026-105192, that can let an attacker run code on the cache server without logging in. The issue affects LMCache 0.3.9 through 0.5.5, plus 0.5.6 release candidates and the development branch. No fixed version is available, so exposed deployments remain at risk until a patched release lands.
Timeline
-
07.10.2026 18:34 2 articles · 2h ago
JFrog discloses unauthenticated remote code execution in LMCache
Initial DisclosureJFrog disclosed a critical vulnerability in LMCache, tracked as CVE-2026-105192, that lets an unauthenticated attacker send a crafted ZeroMQ message to a routable multiprocess cache server and run code as the LMCache process user. The issue affects LMCache 0.3.9 through 0.5.5, plus 0.5.6 release candidates and the development branch, and no fixed version is available. JFrog advised operators not to expose the multiprocess server to routable addresses and to keep the port on the local machine or a trusted cluster network.
Show sources
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely — thehackernews.com — 07.10.2026 18:34
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely — thehackernews.com — 07.10.2026 18:34