Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To determine whether an LMCache deployment is exposed, identify its effective multiprocess listener settings and verify whether an untrusted client can reach that listener. A port number alone is not enough to establish exposure. As of October 7, 2026, a secondary CVE summary reports unauthenticated remote code execution (RCE) involving LMCache multiprocess mode and pickle deserialization, but the reviewed sources do not confirm an official upstream advisory or affected and fixed version range. Read the secondary CVE summary.

What the reported issue does—and does not—establish

The secondary summary dated October 7, 2026 describes CVE-2026-105192 as an unauthenticated RCE issue in LMCache multiprocess mode, involving a ZMQ request path and identifying port 5555 as the default transport port. This is a report from a secondary source, not a verified upstream security advisory. The evidence reviewed does not establish which LMCache versions are affected or which release, if any, fixes the issue. Do not label an installation vulnerable or patched based on its version alone.

LMCache’s optional HTTP POST /run_script endpoint is a separate execution surface. The project documents that it runs caller-supplied Python in-process and is disabled by default in the documented configuration. Its warning about this endpoint is not confirmation of the reported ZMQ issue. The project states: “The restricted builtins are not a security boundary — treat this as full remote code execution and only enable it on a trusted network.” LMCache documentation for the script endpoint

Check the effective deployment configuration

  1. Confirm the mode and record the version. Establish whether the service uses LMCache multiprocess mode. Record the exact installed package or image version, image digest if available, and how the version was obtained. Preserve these details for an advisory check, but do not infer affected or fixed status from them.
  2. Find the actual listener settings. Inspect the running process’s command line and effective configuration for the host or bind address, transport, and port. Check container entrypoints and arguments, Kubernetes Deployments, StatefulSets, or DaemonSets, Services, Helm values, and any environment or launch configuration that can override defaults.
  3. Identify the transport. Determine whether the multiprocess request path uses ZMQ or gRPC. LMCache documents both, including tcp:// for ZMQ and grpc:// for gRPC. Do not assume an HTTP-specific control protects either transport. LMCache quickstart: remote host and transport configuration
  4. Inspect the separate HTTP feature. Review the HTTP frontend configuration and determine whether --run-script-api-enabled is set. If enabled, treat the endpoint as code execution and restrict it to a trusted network, consistent with the project’s warning.

The current development-branch server configuration defines ZMQ, localhost, and port 5555 as defaults. These are source defaults—not proof of the settings used by a running process. Command-line arguments, environment, containers, and orchestration can change them. LMCache server configuration defaults

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Determine whether an untrusted client can reach it

Assess reachability from the trust boundaries that matter for your deployment: the public internet, other tenants, neighboring workloads, or any other network that should not be trusted. Check the full path between those clients and the listener, including the bind address, routing, service exposure, firewall or cloud security-group rules, and network policies.

  • A manifest mentioning port 5555 does not by itself show that the listener is running or reachable.
  • A connector configured with a remote destination does not prove that the server accepts connections from untrusted clients.
  • A localhost default does not prove the live process remains local-only.
  • A custom port is not inherently private; the same reachability checks apply.

LMCache documents configurations with a remote host and custom port, so do not assume a deployment uses the defaults. Verify the effective bind and network path rather than relying on a port number or example configuration. LMCache quickstart

Classify the deployment without overclaiming

What you find What it tells you What it does not establish
Multiprocess mode; listener reachable only by trusted peers The request listener is not reachable across the untrusted boundaries you checked. That the software is unaffected or that other execution surfaces are safe.
Multiprocess mode; listener reachable by an untrusted client The deployment has an exposed request path matching the broad conditions described in the secondary report. That this specific installation is affected; the official version range is unconfirmed.
Port 5555 appears in a manifest or configuration file The port is referenced in that artifact. That a live listener binds to it or that untrusted traffic can reach it.
--run-script-api-enabled is set The separately documented HTTP script endpoint may be enabled; check its frontend and network reachability. That the ZMQ report describes this endpoint.
Installation version is known You have a version to compare against an authoritative advisory when available. That the version is affected or fixed, because no verified range is established here.

What to do if the listener is exposed

  1. Restrict the listener to trusted peers using controls appropriate to its transport and deployment, such as network policy, firewall rules, or cloud security groups.
  2. Verify from the relevant untrusted networks that the listener is no longer reachable; do not rely solely on a configuration change being present.
  3. Check LMCache’s official security advisories and release notes for confirmed affected versions and remediation guidance. Do not treat network restriction as a substitute for a verified upstream fix.
  4. Review the separate HTTP script endpoint. If enabled, limit it to a trusted network or disable it if it is not needed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which LMCache version fixes the RCE?

The reviewed sources do not establish a fixed release or affected version range for CVE-2026-105192. Keep the exact installed version as evidence and consult an official LMCache advisory or release note before making a version-specific vulnerability or patch claim. The secondary summary alone is not enough to identify a safe version.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.