LightLLM 1.2.0 及之前版本存在一个内存耗尽漏洞,该漏洞出现在 NCCL 控制通道中(在通过 --pd_trans_mode nccl 参数启动时)。未认证的攻击者可以利用此漏洞耗尽 KV 传输工作进程的内存。攻击者可通过调用 exposed_set_value 方法存储无大小限制的无界键值对,导致工作进程崩溃并引发节点故障。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103041 | 9.8 CRITICAL | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service |
| CVE-2026-103040 | 9.8 CRITICAL | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Serv |
No comments yet