LMCache: Critical LMCache Vulnerability Lets Unauthenticated Attackers Execute Code With Root Privileges

LMCache: Critical LMCache Vulnerability Lets Unauthenticated Attackers Execute Code With Root Privileges

Critical LMCache Vulnerability (CVE-2026-105192) Enables Remote Code Execution

A severe vulnerability in LMCache, tracked as CVE-2026-105192 (CVSS 9.8), allows unauthenticated remote attackers to execute arbitrary code potentially with root privileges on exposed distributed deployments. The flaw, discovered by JFrog Security Researcher Yuval Moravchick (JFSA-2026-001694382), stems from unsafe Python pickle deserialization in LMCache’s multiprocess ZeroMQ transport.

Affected Versions & Deployment Risks

The vulnerability impacts LMCache versions 0.3.9 and later, including:

  • Latest PyPI release (0.5.5)
  • Release candidates (0.5.6rc1–0.5.6rc3)
  • Development branch (as of October 7, 2026)

LMCache, used for key-value cache sharing in large language model (LLM) inference environments, exposes a ZeroMQ ROUTER socket in distributed mode. While designed for trusted internal communication, the interface lacks authentication, encryption, or access controls, making it vulnerable when bound to a routable network interface (via --host).

Exploitation Mechanism

Attackers can send a crafted ZeroMQ DEALER message to TCP port 5555, triggering pickle.loads on untrusted input during REGISTER_KV_CACHE request processing. Since Python’s pickle deserialization can execute arbitrary code, exploitation occurs before validation, bypassing application-level security checks.

JFrog demonstrated that a single malicious message can achieve command execution, even if the server later rejects the malformed request. The impact varies by configuration:

  • Default single-host deployments (localhost-bound) are not remotely exploitable.
  • Multi-node deployments with routable addresses are at high risk, especially containerized environments where LMCache runs as root, granting attackers full privileges.

Mitigation & Remediation

Until a patch is released, administrators should:

  • Avoid binding LMCache to routable addresses in multiprocess mode.
  • Restrict access via firewalls or network segmentation.
  • Run the process as a non-root user where possible.

Long-term fixes require:

  • Replacing pickle.loads with a secure, schema-validated serialization format.
  • Enforcing ZeroMQ authentication (e.g., CURVE or HMAC).
  • Preventing routable binding unless authentication is explicitly configured.

Firewalls alone are insufficient, as any system with access to the unauthenticated port remains vulnerable.

Source: https://cyberpress.org/critical-lmcache-vulnerability/

LMCache TPRM report: https://www.rankiteo.com/company/lmcache-lab

"id": "lmc1791462291",
"linkid": "lmcache-lab",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology (LLM Inference Environments)',
                        'name': 'LMCache',
                        'type': 'Software'}],
 'attack_vector': 'Network',
 'date_detected': '2026-10-07',
 'description': 'A severe vulnerability in LMCache, tracked as CVE-2026-105192 '
                '(CVSS 9.8), allows unauthenticated remote attackers to '
                'execute arbitrary code potentially with root privileges on '
                'exposed distributed deployments. The flaw stems from unsafe '
                'Python pickle deserialization in LMCache’s multiprocess '
                'ZeroMQ transport.',
 'impact': {'operational_impact': 'Potential full system compromise (root '
                                  'privileges) in distributed deployments',
            'systems_affected': 'LMCache versions 0.3.9 and later (0.5.5, '
                                '0.5.6rc1–0.5.6rc3, and development branch)'},
 'post_incident_analysis': {'corrective_actions': ['Replace pickle.loads with '
                                                   'secure serialization',
                                                   'Enforce ZeroMQ '
                                                   'authentication',
                                                   'Prevent routable binding '
                                                   'without explicit '
                                                   'authentication'],
                            'root_causes': 'Unsafe Python pickle '
                                           'deserialization in ZeroMQ '
                                           'transport, lack of '
                                           'authentication/encryption, and '
                                           'routable binding without access '
                                           'controls'},
 'recommendations': ['Avoid binding LMCache to routable addresses in '
                     'multiprocess mode',
                     'Restrict access via firewalls or network segmentation',
                     'Run the process as a non-root user where possible',
                     'Replace pickle.loads with a secure serialization format',
                     'Enforce ZeroMQ authentication',
                     'Prevent routable binding unless authentication is '
                     'configured'],
 'references': [{'source': 'JFrog Security Research'}],
 'response': {'containment_measures': ['Avoid binding LMCache to routable '
                                       'addresses in multiprocess mode',
                                       'Restrict access via firewalls or '
                                       'network segmentation',
                                       'Run the process as a non-root user '
                                       'where possible'],
              'network_segmentation': 'Recommended',
              'remediation_measures': ['Replace pickle.loads with a secure, '
                                       'schema-validated serialization format',
                                       'Enforce ZeroMQ authentication (e.g., '
                                       'CURVE or HMAC)',
                                       'Prevent routable binding unless '
                                       'authentication is explicitly '
                                       'configured']},
 'title': 'Critical LMCache Vulnerability (CVE-2026-105192) Enables Remote '
          'Code Execution',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-105192 (Unsafe Python pickle '
                            'deserialization in ZeroMQ transport)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.