External risk intelligence

LMCache Remote Code Execution via Unauthenticated ZeroMQ Message.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-105192

The service defaults to binding to localhost, which is typically isolated. While it supports a distributed mode by binding to a routable address for multi-node communication, this configuration is an operator choice rather than the default or inherent design for public-facing exposure.

Missing Authentication

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in LMCache's multiprocess mode that allows unauthenticated remote code execution. This occurs because the system deserializes messages in a way that can be exploited by specially crafted network messages. If LMCache is configured to use a routable address, this could lead to significant compromise of the systems running the affected software.

  • Unauthenticated code execution risk.
  • Affects distributed LMCache deployments.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can send an unauthenticated message to the LMCache transport port, which is exposed by the multiprocess mode. This message triggers a code execution vulnerability because the system processes extension code before validating the request, allowing the attacker to run commands with the privileges of the LMCache process. If the process runs as root, this could lead to complete system compromise.

  • Unauthenticated network access required.
  • Attacker sends crafted ZeroMQ message.
  • Arbitrary code execution as LMCache user.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on the system running the LMCache process by sending specially crafted messages over its ZeroMQ transport port. When LMCache is configured to run in its multiprocess or distributed mode and is exposed on a routable address, it may be vulnerable to remote code execution. Official container images of LMCache run this process as root, increasing the potential impact.

  • System code execution as the LMCache user.
  • Via unauthenticated network messages.
  • Compromise of the host system.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in LMCache's multiprocess mode could allow unauthenticated remote code execution, especially if deployed with a routable address. Infrastructure or platform teams responsible for LMCache should first identify all deployments, assess their reachability and criticality, and confirm the accountable owner for remediation planning.

  • Infrastructure/Platform teams own remediation.
  • Verify routable address deployments first.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LMCache?

LMCache is a software tool used in machine learning environments to manage and share Key-Value (KV) cache blocks. It allows multiple processes or nodes to store and retrieve these cache blocks efficiently, which helps speed up large language model inference by reducing redundant computations. Its multiprocess or distributed mode enables communication between these components using the ZeroMQ messaging library.

What is the vulnerability in CVE-2026-105192?

The vulnerability is a combination of missing authentication (CWE-306) and unsafe deserialization (CWE-502). When LMCache processes messages in distributed mode, it uses the pickle module to deserialize data from incoming ZeroMQ packets before checking if the sender is authorized. Because pickle can be instructed to execute arbitrary functions, a crafted message allows an attacker to run code on the server.

How does an attacker trigger this code execution?

An attacker triggers the bug by sending a specially crafted ZeroMQ message to the transport port used by LMCache. This does not happen if the service is running in a standard single-process mode or if the port is firewalled from the attacker. The vulnerability specifically relies on the system accepting network traffic on the port designated for distributed worker synchronization.

How do I know if my LMCache deployment is at risk?

According to Halo Surface Signal, risk depends on network accessibility. While LMCache defaults to binding to localhost—which is typically isolated—the software supports a distributed mode where it binds to a routable network address to allow peer communication. You are at higher risk if you have explicitly configured your deployment to listen on a routable address accessible from outside your trusted network.

What are the first steps to secure my LMCache environment?

Start by identifying all instances of LMCache currently running in your infrastructure. For those in distributed mode, verify if they are bound to routable network interfaces. If a service must use a routable address, ensure it is restricted by network-level controls like firewalls or VPC rules to prevent unauthorized access to the ZeroMQ transport port until an update is applied.

References