Unauthorized Code Execution in LMCache Distributed Mode by LMCache
CVE-2026-105192
9.8CRITICAL
What is CVE-2026-105192?
The LMCache distributed mode introduces a vulnerability where an unauthenticated ZeroMQ ROUTER allows worker processes to register and share key-value cache blocks. This may lead to code execution as the user running the LMCache process, potentially with elevated privileges if running as root. It involves a msgpack extension that is improperly deserialized using pickle, allowing malicious actors to send specially crafted messages to exploit this flaw.
Affected Version(s)
LMCache 0.3.9
