PatchSiren cyber security CVE debrief
CVE-2026-105192 LMCache CVE debrief
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
- Vendor
- LMCache
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for LMCache instances, especially those running in multiprocess mode or as root, should assess exposure and prioritize patching or mitigations. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure and apply patches or mitigations as available.
Why it matters
Defenders should prioritize verifying exposure of LMCache instances running in multiprocess mode, especially those running as root, and apply patches or mitigations as available due to the critical severity and potential for unauthenticated code execution.
- Unauthenticated code execution as the user the LMCache process runs as
- Potential for privilege escalation if the process runs as root
- Possible disruption of service due to unauthorized code execution
Technical summary
LMCache multiprocess mode opens an unauthenticated ZeroMQ ROUTER, allowing worker processes to register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as.
Defensive priority
Defenders should prioritize verifying exposure of LMCache instances running in multiprocess mode, especially those running as root, and apply patches or mitigations as available.
Recommended defensive actions
- Verify LMCache instances running in multiprocess mode and apply patches or mitigations as available
- Restrict access to the transport port (default 5555) to trusted sources
- Monitor for suspicious activity on the transport port
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected product, attack vector, and technical description. The vulnerability affects LMCache instances running in multiprocess mode, especially those running as root. Defenders should verify exposure and prioritize patching or mitigations. The official CVE Program record and NIST NVD detail page provide additional information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105192 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105192
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105192 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105192
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105192.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/LMCache/LMCache
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://pypi.org/project/lmcache/
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/platform/base/ipc_wrapper.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/LMCache/LMCache/blob/v0.3.9/lmcache/v1/multiprocess/custom_types.py
Supplemental source - technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.