PatchSiren cyber security CVE debrief
CVE-2026-107207 LMCache CVE debrief
LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service. This allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts, potentially leading to unauthorized access, data tampering, or disruption of node communication. The vulnerability can be exploited by adding entries via POST /api/proxies and then using /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.
- Vendor
- LMCache
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for LMCache installations, particularly in environments where internal hosts and services may be exposed, should assess and remediate this vulnerability. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected deployments and implement necessary controls.
Why it matters
This vulnerability allows unauthenticated attackers to bypass the proxy allowlist in LMCache, potentially leading to unauthorized access, data tampering, or disruption of node communication. Defenders should prioritize verification and remediation of this vulnerability in LMCache installations.
- Potential unauthorized access to internal hosts and services
- Possible data tampering or disruption of node communication
- Need for verification of LMCache version and patch application
- Potential for SSRF attacks and bypass of proxy allowlist
Technical summary
The LMCache frontend monitoring service has a server-side request forgery vulnerability that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. This can be exploited by adding entries via POST /api/proxies and then using /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat. Defenders should prioritize verifying and remediating this vulnerability in LMCache installations, particularly in environments where internal hosts and services may be exposed.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in LMCache installations, particularly in environments where internal hosts and services may be exposed.
Recommended defensive actions
- Verify LMCache version and apply patches or updates to remediate the vulnerability
- Review and restrict access to the frontend monitoring service
- Implement additional security measures to detect and prevent SSRF attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is described in the CVE Program record and NVD vulnerability detail page. The source item provides additional metadata and references. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107207 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107207
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107207 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107207
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows SSRF Allowlist Bypa
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107207.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/LMCache/LMCache/issues/5512
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/LMCache/LMCache
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-frontend-node-catalog-allows-ssrf-allowlist-bypass
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.