LMCache exists to stop vLLM servers recomputing prompt prefixes they have already seen. In the mode that shares that cache across nodes, it also opens a door that has no lock.
- CVE-2026-105192, scored 9.8 by JFrog, is an unauthenticated remote code execution in LMCache multiprocess mode.
- The standalone cache server opens a ZeroMQ socket with no CURVE, no ZAP, and no message authentication, and binds to localhost unless an operator sets a routable host.
- A msgpack message reaches pickle.loads while the server is still decoding arguments, so one packet runs code before any handler does.
- Official container images run the cache process as root. A cache used only inside the vLLM process never opens the port.
- No fixed version exists. 0.5.5, the 0.5.6 release candidates, and the development branch all still ship the decode path.
- The mitigation is configuration. Do not bind the multiprocess port to a routable address.
Read the full analysis of the LMCache flaw
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
