CVE-2026-103042
Deferred Deferred - Pending Action

Memory Exhaustion in LightLLM via NCCL Control Channel

Vulnerability report for CVE-2026-103042, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lightllm lightllm to 1.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

LightLLM through version 1.2.0 has a memory exhaustion vulnerability in the NCCL control channel when started with the --pd_trans_mode nccl option. Unauthenticated attackers can exploit this by calling the exposed_set_value method to store unlimited key-value pairs without size restrictions, causing the KV-transfer worker memory to be exhausted. This leads to worker process crashes and node failures.

Detection Guidance

To detect this vulnerability, monitor for excessive memory usage in LightLLM processes, particularly when running with --pd_trans_mode nccl. Check for crashes in KV-transfer worker processes and inspect logs for calls to exposed_set_value with unusually large key-value pairs.

Impact Analysis

This vulnerability can cause denial-of-service conditions by crashing worker processes and nodes, disrupting services that rely on LightLLM. Attackers could exploit it to make systems unavailable, leading to downtime and potential data processing interruptions.

Mitigation Strategies

Immediately upgrade LightLLM to a version that patches this vulnerability. Disable the --pd_trans_mode nccl option if not required. Implement memory usage limits and monitor for suspicious API calls to exposed_set_value.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103042. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart