Weak Hash Vulnerability in LMCache KV Cache Handler Affecting Local Installations
CVE-2026-10813
Key Information:
Badges
What is CVE-2026-10813?
A vulnerability has been identified within LMCache's KV Cache Handler, specifically in the hex_hash_to_int16 function found in the lmcache/integration/vllm/utils.py file. This flaw allows for the use of an insecure hash through local manipulation, resulting in potential cache poisoning. Successfully exploiting this vulnerability is complex and requires a high degree of technical skill. The exploit has been documented and available for use, with ongoing efforts to address the issue through a pending pull request.
Affected Version(s)
LMCache 0.4.0
LMCache 0.4.1
LMCache 0.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
