Skip to content
Critical LMCache Flaw Enables Unauthenticated Remote Code Execution

Critical LMCache Flaw Enables Unauthenticated Remote Code Execution

First seen 8 Oct 2026, 03:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 04:32 UTC
  • •CVE-2026-105192 allows unauthenticated remote code execution in LMCache.
  • •The vulnerability affects versions 0.3.9 to 0.5.5, with a CVSS score of 9.8.
  • •No patch is available; operators are advised to limit server exposure.

A critical vulnerability (CVE-2026-105192) in LMCache, an open-source caching software for large language models, allows unauthenticated attackers to execute code remotely. The flaw exists in the multiprocess mode, where a ZeroMQ socket is exposed without authentication, enabling exploitation via crafted messages. The vulnerability affects versions 0.3.9 through 0.5.5, with no patch available as of October 7, 2026. JFrog, which disclosed the flaw, assigned it a CVSS score of 9.8, indicating critical severity. Attackers can exploit the flaw if the server is configured to listen on a routable address. The default configuration is safer as it binds to localhost. JFrog advises operators to avoid exposing the multiprocess server to untrusted networks until a fix is released. No has been reported in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
CVE-2026-105756 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-105192 published
JFrog disclosed a critical vulnerability in LMCache allowing unauthenticated remote code execution.
Feeds.Feedburner
2026-10-07
JFrog advisory released
JFrog issued an advisory detailing the LMCache vulnerability and recommended mitigations.
Research.Jfrog

More articles in this cluster (4)

Following this threat?

Track JFrog and CVE-2026-105192 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of LMCache are affected?
Versions 0.3.9 through 0.5.5 are affected, including release candidates.
Is there a patch available for this vulnerability?
No, as of October 7, 2026, no patch has been released for CVE-2026-105192.
What should operators do to mitigate the risk?
Operators should avoid binding the multiprocess server to a routable address and keep it on localhost.