Mmastodon TechnologyAI first seen 3 d ago, last 3 d ago, peak #6
Critical unpatched RCE flaw reported in LMCache used by vLLM
Original: 🤖 CVE-2026-105192 (CVSS 9.8): unpatched RCE in LMCache, the KV-cache server used by vLLM. Multiprocess mode exposes an u
Security researchers are flagging CVE-2026-105192, a CVSS 9.8 remote code execution vulnerability in LMCache, the KV-cache server used with the vLLM inference framework. In multiprocess mode, an unauthenticated ZeroMQ socket unpickles attacker-controlled data, allowing code execution as root on official images. Versions 0.3.9 through 0.5.5 are affected, and no fix is currently available, raising concern among teams running AI infrastructure.
Why now: A critical, unpatched vulnerability with root-level remote code execution in widely used AI serving infrastructure is an urgent operational risk.
Evidence
- 🤖 CVE-2026-105192 (CVSS 9.8): unpatched RCE in LMCache, the KV-cache server used by vLLM. Multiprocess mode exposes an unauthenticated ZeroMQ socket that unpickles attacker data — code runs as root on official images. No fix; affects 0.3.9–0.5.5. 🔗 https://… · cloud@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1428757