Critical LMCache Flaw Exposes LLM Servers to Unauth RCE
CVE-2026-105192, a CVSS 9.8 flaw in LMCache's multiprocess server, lets unauthenticated attackers run code on LLM inference infrastructure. No patch exists.

JFrog security researcher Yuval Moravchick disclosed CVE-2026-105192 on October 7: a CVSS 9.8 unauthenticated remote code execution flaw in LMCache, the open-source KV-cache acceleration library used to speed up inference with vLLM and similar LLM serving stacks. No patch exists for any affected release.
What the flaw is
LMCache’s multiprocess mode runs a standalone cache server that accepts connections over a ZeroMQ socket. The server deserializes incoming messages using Python’s pickle format before verifying who sent them. Because pickle deserialization executes arbitrary bytecode, an attacker with network access to that socket can run code with the privileges of the LMCache process. On the official container images, that process runs as root.
Affected versions are LMCache 0.3.9 through 0.5.5 (the current stable release), 0.5.6 release candidates, and the development branch. If you have deployed any of those, the exposure is in place now.
What to do
The JFrog advisory recommends binding the multiprocess server to localhost or a trusted cluster network and avoiding any routable address binding until a patch ships. That is a network-level control, not a fix in the code; it closes the exposure for deployments that can enforce strict network boundaries, but the root cause remains unresolved upstream.
Monitor the LMCache repository for a patch release. Given that this is a disclosed critical CVE with public advisory detail, upstream has the information needed to fix it.
A recurring pattern in AI infrastructure
This is the third unauthenticated RCE in open-source LLM or AI tooling disclosed in roughly seven weeks. In September, researchers found unauthenticated RCE in LightLLM’s config server via the same pickle deserialization mechanism and a critical root RCE in AutoAgent over an unauthenticated TCP socket. Last week, Langflow patched a CVSS 9.9 RCE in its MCP tool handler.
The thread connecting them: these tools were built for speed and ease of deployment, often in research and development contexts where network isolation is assumed rather than enforced. Unauthenticated, network-accessible services that deserialize arbitrary data are a predictable outcome of treating security review as a later step. The LLM serving ecosystem is still early enough that this pattern is going to repeat. Teams deploying these tools in shared or internet-facing environments should treat them with the same operational caution as any production web service, including network segmentation and active monitoring for new disclosures.
LMCache specifically sits between the inference server and the KV cache, with write access to cache state backing active inference jobs. Compromise of that layer has implications beyond the cache server itself.
- [ CRITICAL ]CVE-2026-105192Unauthenticated RCE via pickle deserialization in LMCache multiprocess server
Found this useful? Share it.


