A significant security vulnerability has been identified in LMCache, a widely-used open-source tool that optimizes large language model (LLM) servers such as vLLM. This flaw allows unauthorized individuals to execute code on the cache server without authentication, and currently, there is no available patch to address this issue.
Understanding the LMCache Flaw
The vulnerability resides in LMCache’s multiprocess mode. Here, the cache acts as an independent server, which LLM workers access through the ZeroMQ messaging library. A single network message directed at this server can execute commands under the user account running the LMCache process.
This security gap is only exploitable when the server is configured to listen on a network-accessible address instead of its default localhost setting. JFrog, a cybersecurity firm, revealed this vulnerability on October 7, assigning a critical severity score of 9.8 out of 10, emphasizing the high risk when the server is publicly accessible.
Implications and Affected Versions
The vulnerability, officially cataloged as CVE-2026-105192, impacts LMCache versions from 0.3.9, released in October 2025, up to the latest stable version 0.5.5, including 0.5.6 release candidates and the development branch. No patches are currently available to rectify this flaw.
By default, the multiprocess server restricts access to the local machine, preventing external connections. However, it becomes vulnerable when configured with a routable address, commonly used in multi-node deployments. LMCache’s Kubernetes deployment example configures the server to listen on all network interfaces, increasing potential exposure.
Security Recommendations and Observations
The ZeroMQ socket used by the multiprocess server for worker registrations and data sharing lacks authentication. Messages unpacked using pickle, a Python serialization format, can include executable code, posing a significant risk since the server processes these messages without verifying their type.
JFrog advises against configuring the server with a routable address and recommends keeping it within a local or trusted network. Implementing firewall rules can reduce exposure, but they do not eliminate the risk if unauthorized hosts gain access.
Additionally, a related security issue in vLLM was addressed in version 0.30.0, released on September 22, which prevented a denial-of-service vulnerability caused by malformed cache_salt values used with LMCache’s multiprocess connector. This flaw was tracked as CVE-2026-105756 and rated at a lower severity of 6.5.
Further Security Concerns and Future Outlook
On October 6, a day before the public disclosure of CVE-2026-105192, a GitHub user reported six additional security issues in LMCache, claiming unauthorized access to cached data and command execution without login credentials. However, these claims lack confirmation and have not been assigned CVEs.
The root cause, involving transmitting data from an unauthenticated socket to pickle, reflects a broader issue identified in similar AI inference frameworks in November 2025, known as ShadowMQ. The potential shared origins of LMCache’s code with these frameworks remain unverified, highlighting the need for ongoing vigilance in the cybersecurity community.
