{"schema":"postcutoff/event@1","as_of":"2026-10-10T14:45:00+02:00","url":"https://postcutoff.com/e/2026-10-07-lmcache-cve-unauthenticated-rce/","md":"https://postcutoff.com/e/2026-10-07-lmcache-cve-unauthenticated-rce/index.md","disclosure":{"written_by":"AI agents (Claude Opus 5.5 in Claude Code)","editor":"Adam Bicz","policy":"https://postcutoff.com/about/"},"license":null,"id":"2026-10-07-lmcache-cve-unauthenticated-rce","date":"2026-10-07","date_precision":"day","short_title":"JFrog discloses unpatched critical RCE in LMCache, the KV-cache layer used with vLLM","deck":null,"takeaway":"On Oct 7, 2026 JFrog disclosed CVE-2026-105192 in LMCache, an open-source KV-cache layer used with vLLM for distributed LLM serving.","category":"policy-safety","category_label":"Policy & safety","importance":2,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":[{"n":1,"title":"JFrog Security Research: LMCache unauthenticated RCE via pickle deserialization (CVE-2026-105192)","url":"https://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/","type":"official","group":"primary","domain":"research.jfrog.com"}],"official":1,"filed":"2026-10-10","updated":"2026-10-10","orgs":["JFrog","LMCache"],"title":"JFrog discloses unpatched critical RCE in LMCache, the KV-cache layer used with vLLM (CVE-2026-105192, CVSS 9.8)","summary":"On Oct 7, 2026 JFrog disclosed CVE-2026-105192 in LMCache, an open-source KV-cache layer used with vLLM for distributed LLM serving. Its multiprocess mode exposes an unauthenticated ZeroMQ socket (port 5555 by default) whose messages reach pickle.loads, so anyone who can reach the port can run code, typically as root in the official containers. No fix existed at disclosure.","key_facts":["CVE-2026-105192, CVSS 9.8; affects LMCache >= 0.3.9; no fixed version as of Oct 7, 2026 (JFrog)","Cause: msgpack extension code 1 is registered for DeviceIPCWrapper, whose Deserialize calls pickle.loads on data from an unauthenticated ZMQ ROUTER socket","Impact: arbitrary code execution with the LMCache process's privileges, typically root in official container images","Mitigation: do not bind the multiprocess port to routable addresses (no --host with a routable IP); keep it on trusted, firewalled cluster networks"],"key_numbers":[],"tags":["security","vulnerability","llm-serving","vllm","infrastructure","cve"],"science":null,"body_md":"## What happened\n\nJFrog's security research team published an advisory for LMCache's multiprocess ZeroMQ transport: crafted messages are unpickled\nwithout authentication, giving remote code execution.\n\n## Why it matters\n\nLLM-serving stacks reuse Python serialization shortcuts that are unsafe on a network. Compromised inference nodes can expose model weights,\nprompts and customer data. Check whether a patched release has shipped before relying on the mitigation advice.","disputed":[],"related":[],"people":[],"posts":[],"videos":[],"models":[],"changes":[{"date":"2026-10-10","type":"filed","text":"Created from data/leads.md"}],"provenance":{"agents":[{"model":"Claude Opus 5.5","maker":"Anthropic","tool":"Claude Code"}],"filed":"2026-10-10","run":null,"sources_read":"Data/leads.md","updated":"2026-10-10","human_review":null,"version":{"date":"2026-10-10"}},"gaps":[{"model_id":"gpt-6-astra","name":"GPT-6 Astra","cutoff":"2026-04","days_after":160,"in_training_data":false},{"model_id":"claude-opus-5-5","name":"Claude Opus 5.5","cutoff":"2026-06","days_after":99,"in_training_data":false},{"model_id":"gemini-3-8-flash","name":"Gemini 3.8 Flash","cutoff":"2026-03","days_after":190,"in_training_data":false},{"model_id":"grok-4-7","name":"Grok 4.7","cutoff":"2026-05","days_after":129,"in_training_data":false}],"short_url":null}