Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
ZeroMQ-based remote code execution vulnerability affects LMCache and vLLM deployments

Key Takeaways
- A critical unauthenticated remote code execution vulnerability has been discovered in LMCache's multiprocess mode.
- The flaw affects LMCache deployments using ZeroMQ for communication between cache servers and LLM workers.
- No fixed version or patch is currently available; users are advised to implement network segmentation and restrict ZeroMQ access.
Related Security News

SonicWall Issues Critical Hotfixes for SMA1000 Pre-Authentication SSRF Vulnerability
SonicWall has released hotfixes for four vulnerabilities in its SMA1000 secure mobile appliances, including a critical pre-authentication server-side request forgery (SSRF) flaw rated 10.0 on the CVSS scale. The vulnerability could allow an attacker without valid credentials to send crafted requests through the appliance and reach internal network functions. The company states there is no evidence the flaws are being exploited in the wild, but security researchers warn that the severity rating and pre-authentication nature of the flaw present significant risk to unpatched devices globally.



