Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105192— LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization

Quick assessment

Affected
LMCache LMCache
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LMCache 的多进程模式(也称为分布式模式)会打开一个未经验证的 ZeroMQ ROUTER 套接字,供工作进程注册并共享 KV 缓存块。该套接字上通信的消息使用 msgpack 格式。其中,扩展代码 1 会被传递给 DeviceIPCWrapper.Deserialize 方法,而该方法内部调用了 pickle.loads。由于在服务器仍在解析请求参数、且尚未执行实际处理程序之前,就会完成这一反序列化过程,因此向传输端口(默认端口 5555)发送一条未认证的 ZMQ DEALER 消息,即可以运行 LMCac

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105192

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization
Source: CVE Program / CVE List V5
Vulnerability Description
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
LMCache LMCache 0.3.9 ~ * -

II. Public POCs for CVE-2026-105192

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105192

请登录查看更多情报信息。

Other References for CVE-2026-105192 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105192

No comments yet


Leave a comment