- JFrog said CVE-2026-105192 could let unauthenticated attackers run code on an exposed LMCache server.
- JFrog said the affected LMCache releases run from 0.3.9 through 0.5.5, including 0.5.6 release candidates and the development branch.
- JFrog said no fixed version was available and advised operators not to give the multiprocess server a routable address.
JFrog disclosed on Oct 7, 2026, that a critical vulnerability in LMCache could let an attacker run code on a cache server without logging in. The flaw is tracked as CVE-2026-105192.
The exposure applies when LMCache’s multiprocess server listens on a routable address. JFrog said the vulnerable server receives network messages from LLM workers and that any host able to connect could run code.
LMCache is open-source software used to speed up large language model servers such as vLLM. On the project’s official container images, JFrog said the vulnerable process runs as root.
On this page
LMCache 0.3.9 through 0.5.5 are affected
JFrog said CVE-2026-105192 affects LMCache from version 0.3.9, released in October 2025, through version 0.5.5, the latest stable release. The flaw also appears in 0.5.6 release candidates and the development branch.
The server is reachable from another machine only when an operator configures it to listen on a routable address instead of its default localhost setting. A firewall can lower the risk, JFrog said, but does not remove it because any host that can connect can run code.
Related vLLM flaw could take down concurrent requests
The vLLM advisory gives that flaw a CVSS v3.1 score of 6.5. It affects vLLM 0.25.1 and earlier, although maintainers had not confirmed how far back the issue reaches.
A publicly reachable request with cache_salt set to a forbidden value, such as “/”, could take down the EngineCore process for all concurrent users. The issue requires the built-in LMCache-MP KV connector and LMCache version 0.4.4 or later.
The vLLM advisory credits Patch the Planet, a Trail of Bits and OpenAI collaboration, as the reporter, and says the vulnerability was discovered using GPT-5.5-Cyber as part of the Patch the Planet security initiative. A proposed fix is available in public pull request 51444.
No fixed version was available when JFrog disclosed the flaw. Until a patch ships, JFrog advises operators to keep the multiprocess server’s port on the local machine or a trusted cluster network.
The flaw was found by Yuval Moravchick of JFrog’s security research team.
What to do now
- Do not assign the multiprocess server a routable address, and keep its port on the local machine or on a trusted cluster network until a patch ships.
FAQ
What is CVE-2026-105192?
JFrog said it is a critical LMCache vulnerability that could let an unauthenticated attacker run code on an exposed cache server.
Which LMCache versions are affected?
JFrog said versions 0.3.9 through 0.5.5 are affected, along with 0.5.6 release candidates and the development branch.
When is an LMCache patch available?
JFrog said no fixed version was available when it disclosed the flaw. It advised keeping the multiprocess server’s port local or on a trusted cluster network until a patch ships.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| JFrog said a critical LMCache vulnerability lets an attacker run code on the cache server without logging in, and no fixed version is available. | JFrog, via The Hacker News | Attributed |
| JFrog said the flaw affects LMCache multiprocess mode, where standalone cache servers receive network messages from LLM workers through ZeroMQ. | JFrog, via The Hacker News | Attributed |
| JFrog assigned the flaw a severity score of 9.8 out of 10 for a server bound to a routable address. | JFrog, via The Hacker News | Attributed |
| JFrog said cVE-2026-105192 affects LMCache versions 0.3.9 through 0.5.5, 0.5.6 release candidates, and the development branch, with no fixed version. | JFrog, via The Hacker News | Attributed |
| JFrog said the server is remotely reachable only when an operator configures it to listen on a routable address instead of localhost. | JFrog, via The Hacker News | Attributed |
| On official project container images, the vulnerable LMCache process runs as root, according to JFrog. | JFrog, via The Hacker News | Attributed |
| JFrog said a firewall limiting access to the port lowers risk but does not remove it because any host that can connect can run code. | JFrog, via The Hacker News | Attributed |
| Yuval Moravchick of JFrog's security research team found the flaw. | JFrog, via The Hacker News | Attributed |
| The vLLM advisory gives the related flaw a CVSS v3.1 score of 6.5. | vLLM, via GitHub | Confirmed |
| The related vLLM flaw affects vLLM version 0.25.1 and earlier, although maintainers had not confirmed how far back it reaches. | vLLM, via GitHub | Confirmed |
| A publicly reachable request containing cache_salt set to a forbidden value can kill vLLM's EngineCore process for every concurrent request. | vLLM, via GitHub | Confirmed |
| The related vulnerability requires the built-in LMCache-MP KV connector to be enabled, with LMCache version 0.4.4 or later. | vLLM, via GitHub | Confirmed |
| Patch the Planet reported the related vLLM vulnerability through a collaboration between Trail of Bits and OpenAI. | Patch the Planet, via GitHub | Confirmed |
| The related vLLM vulnerability was discovered using GPT-5.5-Cyber as part of the Patch the Planet security initiative. | Patch the Planet, via GitHub | Confirmed |
| A proposed fix for the related vLLM vulnerability is available in public pull request 51444. | vLLM, via GitHub | Confirmed |
Could not verify
- Whether CVE-2026-105192 has been exploited in the wild is not established
- Whether LMCache maintainers have confirmed or fixed the vulnerability is not established
- How many LMCache deployments are exposed is not established
- Whether any exposed LMCache server has already been attacked is not established



