LMCache 在 0.5.5 及更早版本中存在服务端请求伪造(SSRF)漏洞,该漏洞位于其前端监控服务中。未认证的攻击者可以通过注册任意主机来绕过代理白名单。攻击者可通过向 发送请求添加条目,然后利用 或 访问内部主机,读取响应内容,篡改节点状态或停止心跳检测。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105192 | 9.8 CRITICAL | LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization |
| CVE-2026-107204 | 9.8 CRITICAL | LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint |
| CVE-2026-107206 | 9.4 CRITICAL | LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API |
| CVE-2026-107205 | 8.6 HIGH | LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API |
No comments yet