LMCache CVE -2026-105192: Unpatched Critical RCE Vulnerability
2026-10-09 01:14:10
According to CoinMeta, as reported by Forkast, a vulnerability in LMCache (identified as CVE-2026-105192) has not been patched, posing a serious risk of remote code execution (RCE). This vulnerability affects versions 0.3.9 to 0.5.5, and has a severity score of 9.8 on the CVSS scale. It stems from insecure deserialization, allowing attackers to execute arbitrary code via unauthenticated ZeroMQ router sockets on port 5555 by default, which could potentially lead to a complete system compromise. Although this port is bound to localhost by default, operators often configure it to be routable, thereby expanding the attack surface. As of October 7, 2026, no patching measures have been released yet; it is recommended to immediately restrict network access to port LMCache.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.