# Unpatched LMCache flaw exposes network-accessible cache servers to code execution

_Published Wednesday, October 7, 2026 at 10:39 PM EDT · Security, AI · Latest · Tier 1 — Major_

![Unpatched LMCache flaw exposes network-accessible cache servers to code execution — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyMSiFF8XNm1OpF4uWou7e4nt4fqsuPc0IXyUXhHky9w8ydKkauWm_j0yxdpMsRFlDx-5PHhtAxYNg3Z-rYqvexgILhokXO8tARRTtDHn2P83GOlUhiD6jN7rtkf3Ul1-Hp7O4VyvwV6EGNUgjmcC-B_o_P-xQy9eD7RaTnO_RoDpDwgjTePDvkjC9xso/s1700-nu-rw-lo-l85-e365/lm.jpg)

JFrog disclosed a critical LMCache vulnerability on October 7 that lets unauthenticated attackers run code on its multiprocess cache server, The Hacker News reported. The flaw affects versions 0.3.9 through 0.5.5, the 0.5.6 release candidates and the development branch; no fixed version is available.

A crafted message reaches Python's pickle decoder through an unauthenticated ZeroMQ socket and executes with the cache process's privileges. Remote exposure requires a routable listening address: localhost is the default, but LMCache's example Kubernetes deployment listens on every interface. JFrog advises keeping the port local or within a trusted cluster network. Firewall restrictions reduce risk but leave permitted hosts able to execute code.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html)

---
Canonical: https://techandbusiness.org/newswire/6e_3G-NlJ6kdDST82NYIKV
Published: 2026-10-08T02:39:58.699Z
Story chronology: 2026-10-07T15:34:53.000Z
Retrieved: 2026-10-08T04:44:01.435Z
Publisher: Tech & Business (techandbusiness.org)
