importantSYS.SOURCE: The Hacker News• 2026-10-07T21:04:53+05:30
Unpatched Critical Vulnerability in LMCache Enables Remote Code Execution Without Authentication
A critical unpatched vulnerability (CVE-2026-105192) in LMCache allows unauthenticated remote code execution via crafted ZeroMQ messages in its multiprocess mode. The flaw affects all versions from 0.3.9 to 0.5.6 and remains exploitable until a fix is released.
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.
The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network
*** END OF TRANSMISSION ***