LMCache CVE-2026-105192 unauthenticated RCE, no patch
Pickle on the default ZMQ port in LMCache through 0.5.5

LMCache CVE-2026-105192 unauthenticated RCE, no patch

JFrog Security Research published CVE-2026-105192 on 7 October 2026. It is an unauthenticated remote code execution bug in LMCache, the KV-cache layer often paired with vLLM. CVSS is 9.8. No fixed version has been published.

What happened

In multiprocess mode, also called distributed mode, LMCache opens an unauthenticated ZeroMQ ROUTER so workers can register and share cache blocks. The default port is 5555. While the server is still decoding a REGISTER_KV_CACHE message, an extension hook runs pickle on attacker-controlled data. One DEALER message is enough to execute code as the LMCache user. Official container images run that process as root.

JFrog says the decode path shipped in 0.3.9 and is still present in PyPI 0.5.5, in the 0.5.6 release candidates through 0.5.6rc3, and on the dev branch as of 7 October 2026. A separate issue, CVE-2026-107204, also covers unauthenticated code execution through an internal /run_script endpoint on builds through 0.5.5. That one is a different bug. Do not treat a mitigation for one as a fix for the other.

Who is affected

  • LMCache 0.3.9 through 0.5.5, including 0.5.6 release candidates, when multiprocess or distributed mode is on.
  • Hosts where TCP 5555 is reachable from anything other than trusted worker nodes.
  • Teams running the official image as root, which turns a cache compromise into full host control.

What to do now

Do not expose port 5555. Bind the ZMQ transport to localhost or an isolated worker network, and drop it at the firewall until a fixed release exists. If the port was reachable from a lab, office, or cloud VPC route, assume the host is untrusted and rebuild it. Check whether the internal API is also listening, because CVE-2026-107204 is unpatched on the same version line.

Source: JFrog Security Research, 7 October 2026. JFSA-2026-001694382.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

SonicWall SMA1000 CVE-2026-102255 is CVSS 10
Pre-auth SSRF on SMA 1000 Work Place, hotfix required