A critical flaw in LMCache, the key-value cache layer used in front of vLLM inference servers, lets an unauthenticated attacker run code with a single crafted message. There is a public proof of concept, no patched release, and the container images run as root.
1 article — 2026-10-10
NOT IN CISA KEV — CATALOG 2026.10.08
Authoritative record
Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.
Not listed in CISA's Known Exploited Vulnerabilities catalog as of catalog 2026.10.08. That is not evidence it is not being exploited — the catalog records what CISA has confirmed, and identifiers have been attacked for days before appearing in it.
A critical flaw in LMCache, the key-value cache layer used in front of vLLM inference servers, lets an unauthenticated attacker run code with a single crafted message. There is a public proof of concept, no patched release, and the container images run as root.