Memory Exhaustion Vulnerability in LightLLM by ModelTC
CVE-2026-103042
8.7HIGH
What is CVE-2026-103042?
LightLLM versions up to 1.2.0 are susceptible to a memory exhaustion vulnerability within the NCCL control channel when initiated with the --pd_trans_mode nccl option. This issue allows unauthenticated attackers to overload the KV-transfer worker memory by calling the exposed_set_value method, enabling the storage of unbounded key-value pairs. The lack of size constraints leads to worker process crashes and can cause failures across nodes, posing a significant risk if exploited.
Affected Version(s)
LightLLM 0 <= 1.2.0
