← Back to CVE List
CVE-2026-107207NVD
Vulnerability Summary
LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- LMCache LMCache <= 0.5.5
- LMCache LMCache 0.5.5
External References
- https://github.com/LMCache/LMCache/issues/5512
- https://github.com/LMCache/LMCache
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py#L411-L428
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py#L567-L604
- https://www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-frontend-node-catalog-allows-ssrf-allowlist-bypass