← Back to CVE List
CVE-2026-107205NVD
Vulnerability Summary
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register or deregister instances via /instances, overwrite quotas via /quota endpoints, inject events via /events, and enumerate /directory/keys to disrupt caching and disclose placement metadata.
CVSS v4.0 Base Metrics — Score 8.8 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 8.6 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityHigh
Affected & Patched Versions
- LMCache LMCache <= 0.5.5
- LMCache LMCache 0.5.5
External References
- https://github.com/LMCache/LMCache/issues/5508
- https://github.com/LMCache/LMCache
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/mp_coordinator/config.py#L71
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/mp_coordinator/app.py#L238-L246
- https://www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-mp-coordinator-fleet-control-api