Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-105192

Unauthenticated RCE via pickle deserialization in LMCache multiprocess server

LMCache 0.3.9 through 0.5.5 deserializes ZeroMQ messages with Python pickle before any authentication check, allowing unauthenticated RCE on LLM inference servers. No patch available.

CVE-2026-105192 is a critical unauthenticated remote code execution vulnerability in LMCache, the open-source KV-cache acceleration library used with vLLM and other large language model serving systems. It was disclosed on October 7, 2026 by JFrog security researcher Yuval Moravchick.

Affected versions

LMCache 0.3.9 through 0.5.5 (current stable), including 0.5.6 release candidates and the development branch. No patched release exists as of disclosure.

What the flaw is

When LMCache operates in multiprocess mode, it runs a standalone cache server that accepts connections over a ZeroMQ socket. The server deserializes incoming messages using Python’s pickle format without verifying the sender’s identity first. Because Python pickle deserialization executes arbitrary bytecode, an attacker with network access to the socket can achieve code execution with the privileges of the LMCache process. On the official container images, that process runs as root.

Mitigation

Bind the multiprocess server to localhost or a trusted cluster network. Avoid exposing the ZeroMQ port on any routable or internet-facing interface until a patch is released. See the JFrog advisory for full details.