CVE-2026-105192: LMCache CVSS 9.8 RCE still unpatched
LMCache unauthenticated ZMQ remote code execution

CVE-2026-105192: LMCache CVSS 9.8 RCE still unpatched

The cache layer many teams bolt onto vLLM has an unauthenticated remote code execution flaw, and as of 7 October 2026 there is still no fixed release. JFrog scores CVE-2026-105192 at CVSS 9.8.

What happened

LMCache multiprocess mode opens a ZeroMQ port so workers can share KV-cache blocks. JFrog found that a single unauthenticated message on that socket is deserialized with Python pickle before the handler runs. Default port is 5555. Official container images run the process as root, so a hit on an exposed node is a host-level compromise of the container.

The unsafe path shipped in 0.3.9 and is still present in 0.5.5, in 0.5.6 release candidates through 0.5.6rc3, and on the dev branch JFrog reviewed on 7 October. A proof of concept was published with the advisory. Localhost-only bindings are not remotely reachable. Multi-node setups that set a routable address are.

Who is affected

Anyone running LMCache 0.3.9 or later in distributed mode with the ZMQ transport reachable beyond the host. That includes Kubernetes and multi-node inference stacks where peers are expected to connect over the network.

  • Affected: 0.3.9 through at least 0.5.5, plus reviewed 0.5.6 release candidates.
  • Not remotely exploitable if the transport stays on localhost.
  • No vendor patch was available at disclosure.

What to do now

Do not expose the LMCache ZMQ port. Firewall it to the inference nodes that must talk, or bind it to localhost until a fixed version exists. Assume a container that was reachable from an untrusted network may already be compromised, and rotate any cloud credentials that process could read.

Source: JFrog Security Research, JFSA-2026-001694382. CVE record: CVE-2026-105192.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

FortiBleed: FBI says 86,644 FortiGates compromised, lockouts continue
FortiGate admin lockout stolen VPN credentials