JFrog discloses unpatched critical RCE in LMCache, the KV-cache layer used with vLLM
Confirmed
The takeaway
On Oct 7, 2026 JFrog disclosed CVE-2026-105192 in LMCache, an open-source KV-cache layer used with vLLM for distributed LLM serving.
Status
- Claim
Confirmed
- Our reporting
- High confidence
- Importance
- 2 of 5
- Last verified
- 10 October 2026
Your AI and this story
- GPT-6 Astra160 days after its cutoff
- Claude Opus 5.599 days after its cutoff
- Gemini 3.8 Flash190 days after its cutoff
- Grok 4.7129 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 99 days before it.
Key facts
- CVE-2026-105192, CVSS 9.8; affects LMCache >= 0.3.9; no fixed version as of Oct 7, 2026 (JFrog)
- Cause: msgpack extension code 1 is registered for DeviceIPCWrapper, whose Deserialize calls pickle.loads on data from an unauthenticated ZMQ ROUTER socket
- Impact: arbitrary code execution with the LMCache process’s privileges, typically root in official container images
- Mitigation: do not bind the multiprocess port to routable addresses (no --host with a routable IP); keep it on trusted, firewalled cluster networks
What happened
JFrog’s security research team published an advisory for LMCache’s multiprocess ZeroMQ transport: crafted messages are unpickled without authentication, giving remote code execution.
Why it matters
LLM-serving stacks reuse Python serialization shortcuts that are unsafe on a network. Compromised inference nodes can expose model weights, prompts and customer data. Check whether a patched release has shipped before relying on the mitigation advice.
Sources
1 source from 1 site. Numbers match the chips in the text.
1 source: 1 primary
Primary
- JFrog Security Research: LMCache unauthenticated RCE via pickle deserialization (CVE-2026-105192)research.jfrog.com, official
Changes
- Filed from data/leads.md