// AI threat desk · 8 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalRCECVSS 9.8; 6.5 for related vLLM flaw

JFrog discloses LMCache flaw that could let attackers run code

JFrog said an unauthenticated attacker could run code on exposed LMCache cache servers. It disclosed the critical flaw on Oct 7, 2026, and assigned it a 9.8 score.

AI-generated image of security analysts monitoring cache servers and security dashboards.
AI-generated image, not a photo of the event.
Key takeaways
  • JFrog said CVE-2026-105192 could let unauthenticated attackers run code on an exposed LMCache server.
  • JFrog said the affected LMCache releases run from 0.3.9 through 0.5.5, including 0.5.6 release candidates and the development branch.
  • JFrog said no fixed version was available and advised operators not to give the multiprocess server a routable address.

JFrog disclosed on Oct 7, 2026, that a critical vulnerability in LMCache could let an attacker run code on a cache server without logging in. The flaw is tracked as CVE-2026-105192.

The exposure applies when LMCache’s multiprocess server listens on a routable address. JFrog said the vulnerable server receives network messages from LLM workers and that any host able to connect could run code.

LMCache is open-source software used to speed up large language model servers such as vLLM. On the project’s official container images, JFrog said the vulnerable process runs as root.

On this page

LMCache 0.3.9 through 0.5.5 are affected

JFrog said CVE-2026-105192 affects LMCache from version 0.3.9, released in October 2025, through version 0.5.5, the latest stable release. The flaw also appears in 0.5.6 release candidates and the development branch.

The server is reachable from another machine only when an operator configures it to listen on a routable address instead of its default localhost setting. A firewall can lower the risk, JFrog said, but does not remove it because any host that can connect can run code.

The vLLM advisory gives that flaw a CVSS v3.1 score of 6.5. It affects vLLM 0.25.1 and earlier, although maintainers had not confirmed how far back the issue reaches.

A publicly reachable request with cache_salt set to a forbidden value, such as “/”, could take down the EngineCore process for all concurrent users. The issue requires the built-in LMCache-MP KV connector and LMCache version 0.4.4 or later.

The vLLM advisory credits Patch the Planet, a Trail of Bits and OpenAI collaboration, as the reporter, and says the vulnerability was discovered using GPT-5.5-Cyber as part of the Patch the Planet security initiative. A proposed fix is available in public pull request 51444.

No fixed version was available when JFrog disclosed the flaw. Until a patch ships, JFrog advises operators to keep the multiprocess server’s port on the local machine or a trusted cluster network.

The flaw was found by Yuval Moravchick of JFrog’s security research team.

What to do now

  1. Do not assign the multiprocess server a routable address, and keep its port on the local machine or on a trusted cluster network until a patch ships.

FAQ

What is CVE-2026-105192?

JFrog said it is a critical LMCache vulnerability that could let an unauthenticated attacker run code on an exposed cache server.

Which LMCache versions are affected?

JFrog said versions 0.3.9 through 0.5.5 are affected, along with 0.5.6 release candidates and the development branch.

When is an LMCache patch available?

JFrog said no fixed version was available when it disclosed the flaw. It advised keeping the multiprocess server’s port local or on a trusted cluster network until a patch ships.

Sources

  1. Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments, uncaught downstream `ValueError` denial of service, GitHubPrimary
  2. Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely, The Hacker News
How we checked this story
ClaimSourceStatus
JFrog said a critical LMCache vulnerability lets an attacker run code on the cache server without logging in, and no fixed version is available.JFrog, via The Hacker NewsAttributed
JFrog said the flaw affects LMCache multiprocess mode, where standalone cache servers receive network messages from LLM workers through ZeroMQ.JFrog, via The Hacker NewsAttributed
JFrog assigned the flaw a severity score of 9.8 out of 10 for a server bound to a routable address.JFrog, via The Hacker NewsAttributed
JFrog said cVE-2026-105192 affects LMCache versions 0.3.9 through 0.5.5, 0.5.6 release candidates, and the development branch, with no fixed version.JFrog, via The Hacker NewsAttributed
JFrog said the server is remotely reachable only when an operator configures it to listen on a routable address instead of localhost.JFrog, via The Hacker NewsAttributed
On official project container images, the vulnerable LMCache process runs as root, according to JFrog.JFrog, via The Hacker NewsAttributed
JFrog said a firewall limiting access to the port lowers risk but does not remove it because any host that can connect can run code.JFrog, via The Hacker NewsAttributed
Yuval Moravchick of JFrog's security research team found the flaw.JFrog, via The Hacker NewsAttributed
The vLLM advisory gives the related flaw a CVSS v3.1 score of 6.5.vLLM, via GitHubConfirmed
The related vLLM flaw affects vLLM version 0.25.1 and earlier, although maintainers had not confirmed how far back it reaches.vLLM, via GitHubConfirmed
A publicly reachable request containing cache_salt set to a forbidden value can kill vLLM's EngineCore process for every concurrent request.vLLM, via GitHubConfirmed
The related vulnerability requires the built-in LMCache-MP KV connector to be enabled, with LMCache version 0.4.4 or later.vLLM, via GitHubConfirmed
Patch the Planet reported the related vLLM vulnerability through a collaboration between Trail of Bits and OpenAI.Patch the Planet, via GitHubConfirmed
The related vLLM vulnerability was discovered using GPT-5.5-Cyber as part of the Patch the Planet security initiative.Patch the Planet, via GitHubConfirmed
A proposed fix for the related vLLM vulnerability is available in public pull request 51444.vLLM, via GitHubConfirmed

Could not verify

  • Whether CVE-2026-105192 has been exploited in the wild is not established
  • Whether LMCache maintainers have confirmed or fixed the vulnerability is not established
  • How many LMCache deployments are exposed is not established
  • Whether any exposed LMCache server has already been attacked is not established
Explore with AI