PulseAugur
中
实时 02:26:48
English(EN) 🤖 Unpatched critical RCE in LMCache, the LLM KV-cache server used with vLLM: in multiprocess mode an unauthenticated attacker can run code over ZeroMQ. No fixed

vLLM 的 LMCache 中发现关键远程代码执行漏洞

在 LMCache 中发现了一个关键的远程代码执行漏洞,LMCache 是与 vLLM 一起用于 LLM KV 缓存的服务器。该漏洞存在于多进程模式下,允许未经身份验证的攻击者通过 ZeroMQ 执行代码。目前,LMCache 还没有可用的修复版本。 AI

影响 LMCache 中的这一关键漏洞可能使使用 vLLM 的 AI 推理系统面临安全风险。

排序理由 在 AI 基础设施使用的特定软件组件中发现漏洞。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

vLLM 的 LMCache 中发现关键远程代码执行漏洞

本文如何被排名

Signal score
1 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
在 AI 基础设施使用的特定软件组件中发现漏洞。
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
infra, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Same-day
Cluster formed today. Ranking reflects the current source set at time of score.
Coverage growth since scoring
+1 source(s) since last score
New sources have picked up this story since our last re-score. Score will update on the next scoring pass.

完整方法见我们的编辑标准。

报道来源 [2]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 CVE-2026-105192 (CVSS 9.8): vLLM使用的KV缓存服务器LMCache中存在未修补的RCE漏洞。多进程模式暴露了未经身份验证的ZeroMQ套接字,该套接字允许反序列化

    🤖 CVE-2026-105192 (CVSS 9.8): unpatched RCE in LMCache, the KV-cache server used by vLLM. Multiprocess mode exposes an unauthenticated ZeroMQ socket that unpickles attacker data — code runs as root on official images. No fix; affects 0.3.9–0.5.5. 🔗 https:// thehackernews.com/2026…

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 LMCache 中存在未修复的关键 RCE 漏洞,该 LLM KV 缓存服务器与 vLLM 一起使用:在多进程模式下,未经身份验证的攻击者可以通过 ZeroMQ 执行代码。尚未修复

    🤖 Unpatched critical RCE in LMCache, the LLM KV-cache server used with vLLM: in multiprocess mode an unauthenticated attacker can run code over ZeroMQ. No fixed version available yet. 🔗 https:// thehackernews.com/2026/10/unpa tched-critical-lmcache-flaw-lets.html # CyberSec # Exp…