Full Report
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network
Analysis Summary
# Vulnerability: Unauthenticated Remote Code Execution in LMCache via Pickle Deserialization
## CVE Details
- **CVE ID:** CVE-2026-105192
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-502 (Deserialization of Untrusted Data)
## Affected Systems
- **Products:** LMCache (Open-source LLM caching software)
- **Versions:** 0.3.9 through 0.5.5 (Latest stable), 0.5.6 release candidates, and current development branch.
- **Configurations:**
- Affects systems running in **multiprocess mode** where the cache runs as a standalone server.
- Specifically vulnerable when the server is configured to listen on a **routable network address** (non-localhost) or deployed via the default Kubernetes DaemonSet example.
## Vulnerability Description
The flaw exists in LMCache's use of the ZeroMQ messaging library for communication between the cache server and LLM workers. The server uses Python’s `pickle` module to unpack data received over the network.
Because `pickle` is inherently insecure when used on untrusted data, an attacker can craft a malicious ZeroMQ message that executes arbitrary Python code during the deserialization process. The server processes this data before verifying the message type or sender identity, and since the ZeroMQ socket lacks authentication, any network-adjacent attacker can trigger the execution.
## Exploitation
- **Status:** PoC documented by JFrog researchers; no widespread exploitation in the wild reported yet.
- **Complexity:** Low (Requires sending a single crafted network message).
- **Attack Vector:** Network (If bound to a routable IP) / Adjacent (If restricted to a cluster network).
## Impact
- **Confidentiality:** Total (Full access to data and environment variables).
- **Integrity:** Total (Ability to modify files, cache data, or system configurations).
- **Availability:** Total (Ability to crash the service or take over the host).
- **Note:** In official LMCache container images, the process often runs as **root**, granting the attacker full system control.
## Remediation
### Patches
- **None:** As of the latest report, there is **no fixed version available**.
### Workarounds
- **Bind to Localhost:** Ensure the multiprocess server listens only on `127.0.0.1` unless external access is strictly necessary.
- **Network Isolation:** If a routable address is required, place the server behind a strict firewall or within a trusted VPC/Cluster network.
- **Avoid Multiprocess Mode:** Run LMCache within a single vLLM process (which does not open the vulnerable ZeroMQ port) if performance requirements allow.
## Detection
- **Indicators of Compromise:** Unusual outbound network connections from the LMCache process; unexpected Python processes spawned by the cache server.
- **Detection Methods:** Monitor ZeroMQ traffic on the LMCache port (default varies by config) for serialized pickle payloads. Audit container logs for unauthorized command execution.
## References
- **JFrog Advisory:** hxxps://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/
- **CVE Record:** hxxps://www.cve.org/CVERecord?id=CVE-2026-105192
- **LMCache Repository:** hxxps://github.com/LMCache/LMCache