CVE-2026-105192
Received Received - Intake

LMCache Distributed Mode Unauthenticated Code Execution

Vulnerability report for CVE-2026-105192, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: JFrog

Description

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
LMCache LMCache 0.3.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated remote code execution via a ZeroMQ ROUTER socket in LMCache's multiprocess mode. An attacker can send a specially crafted msgpack message with extension code 1 to the default port 5555. This triggers pickle.loads in DeviceIPCWrapper.Deserialize before input validation, executing arbitrary code as the user running the LMCache process. Official container images run this process as root.

Detection Guidance

Check if LMCache is running in multiprocess mode by inspecting running processes for the LMCache service and verifying if port 5555 is open and listening on localhost or a routable address. Use commands like 'netstat -tulnp | grep 5555' or 'ss -tulnp | grep 5555' to check for open ports. Inspect logs for unauthorized ZeroMQ ROUTER connections or unexpected pickle deserialization events.

  • Verify LMCache process ownership with 'ps aux | grep LMCache' to confirm if it runs as root.
  • Monitor network traffic for unauthenticated DEALER messages to port 5555 using tools like Wireshark or tcpdump.
Impact Analysis

An attacker could gain full control of the system running LMCache, install malware, steal data, or disrupt services. Since the transport binds to localhost by default, local network access is sufficient to exploit this. If the operator exposed the port to a routable address, remote attackers could also exploit it.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and system integrity. GDPR requires adequate security measures to protect personal data, while HIPAA mandates safeguards for protected health information. A remote code execution flaw could lead to unauthorized access, data breaches, or system compromise, resulting in regulatory penalties and loss of trust.

Mitigation Strategies

Immediately stop LMCache multiprocess mode if enabled. Disable the ZeroMQ ROUTER socket by not using the --host flag for routable addresses. Update LMCache to a patched version if available. Restrict network access to port 5555 using firewalls to allow only trusted internal communications.

  • Run LMCache processes with least-privilege user accounts instead of root to limit potential damage from exploitation.
  • Monitor for signs of compromise such as unexpected process execution or unauthorized network connections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart