PT-2026-107458 · Lmcache · Lmcache

·

CVE-2026-105192

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LMCache versions 0.3.9 through 0.5.6
Description In multiprocess or distributed mode, the software opens an unauthenticated ZeroMQ ROUTER socket to allow worker processes to register and share KV cache blocks. The server uses msgpack for messages and passes extension code 1 to the DeviceIPCWrapper.Deserialize function, which subsequently calls pickle.loads before request arguments are decoded or the handler is executed. An unauthenticated ZMQ DEALER message sent to the transport port (default 5555) can lead to arbitrary code execution with the privileges of the user running the LMCache process, which is root in official container images. This issue is exploitable when the operator sets a routable address using the --host parameter for multi-node deployments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid setting a routable address with the --host parameter to ensure the transport binds only to localhost.

Deserialization of Untrusted Data

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105192

Affected Products

Lmcache