cd /news/ai-infrastructure/lmcache-cve-2026-105192-unpatched-cr… · home › topics › ai-infrastructure › article
[ARTICLE · art-147307] src=forkast.news ↗ pub= topic=ai-infrastructure verified=true sentiment=↓ negative

LMCache CVE-2026-105192: Unpatched Critical RCE in the LLM KV Cache Layer

LMCache versions 0.3.9 through 0.5.5 contain an unpatched critical remote code execution vulnerability, tracked as CVE-2026-105192 with a CVSS score of 9.8, according to the National Vulnerability Database. The flaw stems from insecure deserialization in LMCache's distributed mode, which opens an unauthenticated ZeroMQ ROUTER socket on port 5555 by default; a single unauthenticated ZeroMQ DEALER message triggers pickle.loads on attacker-controlled data via extension code 1 passed to DeviceIPCWrapper.Deserialize, executing arbitrary code with the privileges of the LMCache process, which runs as root in official container images. As of October 7, 2026, no patch exists, and the EPSS score sits at 0.671%, so operators are advised to restrict network access to port 5555 and audit deployments where the --host flag has been set to a routable address.

by read2 min views1 publishedOct 8, 2026
LMCache CVE-2026-105192: Unpatched Critical RCE in the LLM KV Cache Layer
Image: Forkast (auto-discovered)

LMCache, the distributed key-value cache layer for the vLLM inference engine, exposes an unauthenticated remote code execution (RCE) path via CVE-2026-105192. With a CVSS score of 9.8, this flaw affects versions 0.3.9 through 0.5.5. As of October 7, 2026, the vulnerability remains unpatched. The flaw stems from insecure deserialization within the infrastructure designed to accelerate LLM inference, a component increasingly central to the economic viability of agent-based workloads.

The technical mechanism centers on the LMCache distributed mode, which opens an unauthenticated ZeroMQ ROUTER socket on port 5555 by default. While the transport is intended for worker registration and KV cache block sharing, it lacks authentication. The system processes messages using msgpack; specifically, extension code 1 passed to DeviceIPCWrapper.Deserialize triggers pickle.loads on attacker-controlled data. This execution occurs during request argument decoding, before any handler logic. A single, unauthenticated ZeroMQ DEALER message to port 5555 executes arbitrary code with the privileges of the LMCache process. Because official container images run this as root, the result is total system compromise.

Compromising the inference acceleration layer grants an attacker control over the agent’s underlying cache, effectively poisoning the infrastructure. While the transport binds to localhost by default, operators frequently configure a routable address using the --host flag for multi-node deployments. In these configurations, the service becomes accessible over the network, significantly expanding the attack surface.

LMCache’s architecture exemplifies the trust-through-defaults pattern. The transport port 5555 is open and unauthenticated by design. This mirrors failures in systems like Cisco NX-API, HPE ClearPass, Splunk MCP Server, and DB-GPT. In these environments, the assumption that internal network traffic is inherently trusted leads to the omission of authentication for critical functions (CWE-306).

As of October 7, 2026, no patch exists to remediate the insecure deserialization. The reliance on pickle.loads in a distributed, unauthenticated context creates a persistent risk for any environment where the LMCache port is reachable. While the EPSS score sits at 0.671%, the critical nature of the RCE and the lack of a patch necessitate immediate isolation of the LMCache port.

The integration of LMCache with vLLM suggests that potential exposure is not limited to niche deployments. Organizations using LMCache to optimize inference performance for agent workloads must account for this in their threat models. Until a patch is released, the primary mitigation involves restricting network access to the LMCache port and auditing the deployment environment for any instances where the --host flag has been set to a routable address.

── more in #ai-infrastructure 4 stories · sorted by recency
── more on @lmcache 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/lmcache-cve-2026-105…] indexed:0 read:2min 2026-10-08 · —