Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Earth’s center is moving, and NASA just measured it

    October 8, 2026

    Tropical Storm Isaias forms, is forecast to become a hurricane and hit US Gulf Coast this week

    October 8, 2026

    US bars Fiji-based man over corruption tied to China | Corruption News

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Earth’s center is moving, and NASA just measured it
    • Tropical Storm Isaias forms, is forecast to become a hurricane and hit US Gulf Coast this week
    • US bars Fiji-based man over corruption tied to China | Corruption News
    • Far-right Vox sees election as its big chance to reshape Spain – POLITICO
    • Managers are using AI to write performance reviews – and it shows
    • Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
    • U.S. Investors Want To Up Their Crypto Holdings: Charles Schwab
    • Can WarWilding defend Poland’s borders and save Europe’s last ancient forest?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalOct 07, 2026Vulnerability / Artificial Intelligence

    A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.

    The flaw is in LMCache’s multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network message to that server can run commands as the user the LMCache process runs as.

    The server can be reached from another machine only when an operator sets it to listen on a routable address, rather than the localhost it uses by default.

    JFrog disclosed the flaw on October 7 and assigned it a severity score of 9.8 out of 10, in the critical range, the rating it gives a server bound to a routable address.

    The vulnerability, tracked as CVE-2026-105192, affects LMCache from version 0.3.9, released in October 2025, through 0.5.5, the latest stable release, and is also present in the 0.5.6 release candidates and the development branch. No fixed version exists.

    Cybersecurity

    Whether a server is exposed comes down to one setting. By default, the multiprocess server listens only on the local machine, so another host cannot reach it. It becomes reachable when an operator starts it with a routable address, much like multi-node deployments share a cache across machines.

    LMCache’s own example Kubernetes deployment starts the server that way, listening on every network interface. A copy of LMCache running inside a single vLLM process does not open the port at all.

    The ZeroMQ socket the multiprocess server opens for worker processes to register and share cached data has no authentication. One type of message is unpacked with pickle, a Python format that can carry code and run it as the data is decoded. The server unpacks it while still reading the message’s arguments, before any check of the message’s type, so a crafted message can run the sender’s code.

    The code runs with the privileges of the LMCache process. On the project’s official container images, that process runs as root, according to JFrog. The flaw was found by Yuval Moravchick of JFrog’s security research team.

    There is no patched release. Until one ships, JFrog advises operators not to assign the multiprocess server a routable address and to keep its port on the local machine or on a trusted cluster network. A firewall that limits who can reach the port lowers the risk but does not remove it, because any host that can still open a connection can run code.

    LMCache has not published a security advisory for the flaw. JFrog’s advisory does not provide operators with a way to determine whether a server has already been attacked.

    Other Reports and a Related vLLM Fix

    Separately, a GitHub user opened six additional LMCache security reports on October 6, the day before CVE-2026-105192 was made public. They allege unauthenticated access to cached data belonging to different tenants, as well as to several network services that execute commands without a login.

    Cybersecurity

    The reports come from one account, rest on proof-of-concept claims, and have no CVE, no confirmation from the maintainers, and no fix. One points to a default LMCache that has since changed: an admin HTTP server that listened on every network interface in 0.5.5 listens only on the local host in the 0.5.6 release candidates.

    A related flaw in vLLM is already fixed. Before version 0.30.0, released September 22, a single request carrying a malformed cache_salt value could crash the engine on deployments that use the LMCache multiprocess connector, a denial-of-service bug tracked as CVE-2026-105756. It is rated 6.5 and does not allow code execution.

    The core mistake, handing data from an unauthenticated network socket to pickle, is the same one researchers found across other AI inference frameworks in November 2025, in a group of flaws they called ShadowMQ. Whether LMCache’s code shares a common source with those projects has not been established.

    Attackers Code critical Flaw lets LMCache remotely Run unauthenticated unpatched
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Ransomware recovery CEO charged over secret ransom payments

    Citizen Lab Slams Trump, ‘Techno-Fascist’ Executives

    FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

    OpenAI Agent Escape Causes Wikimedia Service Outage

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Earth’s center is moving, and NASA just measured it

    October 8, 2026

    Tropical Storm Isaias forms, is forecast to become a hurricane and hit US Gulf Coast this week

    October 8, 2026

    US bars Fiji-based man over corruption tied to China | Corruption News

    October 8, 2026

    Far-right Vox sees election as its big chance to reshape Spain – POLITICO

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Earth’s center is moving, and NASA just measured it

    October 8, 2026

    Tropical Storm Isaias forms, is forecast to become a hurricane and hit US Gulf Coast this week

    October 8, 2026

    US bars Fiji-based man over corruption tied to China | Corruption News

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.