Critical LMCache Vulnerability (CVE-2026-105192) Enables Remote Code Execution
A severe vulnerability in LMCache, tracked as CVE-2026-105192 (CVSS 9.8), allows unauthenticated remote attackers to execute arbitrary code potentially with root privileges on exposed distributed deployments. The flaw, discovered by JFrog Security Researcher Yuval Moravchick (JFSA-2026-001694382), stems from unsafe Python pickle deserialization in LMCache’s multiprocess ZeroMQ transport.
Affected Versions & Deployment Risks
The vulnerability impacts LMCache versions 0.3.9 and later, including:
- Latest PyPI release (0.5.5)
- Release candidates (0.5.6rc1–0.5.6rc3)
- Development branch (as of October 7, 2026)
LMCache, used for key-value cache sharing in large language model (LLM) inference environments, exposes a ZeroMQ ROUTER socket in distributed mode. While designed for trusted internal communication, the interface lacks authentication, encryption, or access controls, making it vulnerable when bound to a routable network interface (via --host).
Exploitation Mechanism
Attackers can send a crafted ZeroMQ DEALER message to TCP port 5555, triggering pickle.loads on untrusted input during REGISTER_KV_CACHE request processing. Since Python’s pickle deserialization can execute arbitrary code, exploitation occurs before validation, bypassing application-level security checks.
JFrog demonstrated that a single malicious message can achieve command execution, even if the server later rejects the malformed request. The impact varies by configuration:
- Default single-host deployments (localhost-bound) are not remotely exploitable.
- Multi-node deployments with routable addresses are at high risk, especially containerized environments where LMCache runs as root, granting attackers full privileges.
Mitigation & Remediation
Until a patch is released, administrators should:
- Avoid binding LMCache to routable addresses in multiprocess mode.
- Restrict access via firewalls or network segmentation.
- Run the process as a non-root user where possible.
Long-term fixes require:
- Replacing pickle.loads with a secure, schema-validated serialization format.
- Enforcing ZeroMQ authentication (e.g., CURVE or HMAC).
- Preventing routable binding unless authentication is explicitly configured.
Firewalls alone are insufficient, as any system with access to the unauthenticated port remains vulnerable.
Source: https://cyberpress.org/critical-lmcache-vulnerability/
LMCache TPRM report: https://www.rankiteo.com/company/lmcache-lab
"id": "lmc1791462291",
"linkid": "lmcache-lab",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology (LLM Inference Environments)',
'name': 'LMCache',
'type': 'Software'}],
'attack_vector': 'Network',
'date_detected': '2026-10-07',
'description': 'A severe vulnerability in LMCache, tracked as CVE-2026-105192 '
'(CVSS 9.8), allows unauthenticated remote attackers to '
'execute arbitrary code potentially with root privileges on '
'exposed distributed deployments. The flaw stems from unsafe '
'Python pickle deserialization in LMCache’s multiprocess '
'ZeroMQ transport.',
'impact': {'operational_impact': 'Potential full system compromise (root '
'privileges) in distributed deployments',
'systems_affected': 'LMCache versions 0.3.9 and later (0.5.5, '
'0.5.6rc1–0.5.6rc3, and development branch)'},
'post_incident_analysis': {'corrective_actions': ['Replace pickle.loads with '
'secure serialization',
'Enforce ZeroMQ '
'authentication',
'Prevent routable binding '
'without explicit '
'authentication'],
'root_causes': 'Unsafe Python pickle '
'deserialization in ZeroMQ '
'transport, lack of '
'authentication/encryption, and '
'routable binding without access '
'controls'},
'recommendations': ['Avoid binding LMCache to routable addresses in '
'multiprocess mode',
'Restrict access via firewalls or network segmentation',
'Run the process as a non-root user where possible',
'Replace pickle.loads with a secure serialization format',
'Enforce ZeroMQ authentication',
'Prevent routable binding unless authentication is '
'configured'],
'references': [{'source': 'JFrog Security Research'}],
'response': {'containment_measures': ['Avoid binding LMCache to routable '
'addresses in multiprocess mode',
'Restrict access via firewalls or '
'network segmentation',
'Run the process as a non-root user '
'where possible'],
'network_segmentation': 'Recommended',
'remediation_measures': ['Replace pickle.loads with a secure, '
'schema-validated serialization format',
'Enforce ZeroMQ authentication (e.g., '
'CURVE or HMAC)',
'Prevent routable binding unless '
'authentication is explicitly '
'configured']},
'title': 'Critical LMCache Vulnerability (CVE-2026-105192) Enables Remote '
'Code Execution',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'CVE-2026-105192 (Unsafe Python pickle '
'deserialization in ZeroMQ transport)'}