The cache unpickles the message before it checks what kind of message it is
2026-10-10Security
A critical flaw in LMCache, the key-value cache layer used in front of vLLM inference servers, lets an unauthenticated attacker run code with a single crafted message. There is a public proof of concept, no patched release, and the container images run as root.