CVE-2026-107205

Source
https://cve.org/CVERecord?id=CVE-2026-107205
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107205.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107205
Published
2026-10-07T15:24:04Z
Modified
2026-10-08T02:49:28Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API
Details

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register or deregister instances via /instances, overwrite quotas via /quota endpoints, inject events via /events, and enumerate /directory/keys to disrupt caching and disclose placement metadata.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107205.json"
}
References

Affected packages

Git / github.com/lmcache/lmcache

Affected ranges

Type
GIT
Repo
https://github.com/lmcache/lmcache
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.5.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
nightly
nightly-cu129
nightly-cu13
nightly-musa
nightly-rocm
nightly-rocm-2026-09-09
nightly-rocm-2026-09-09-cu129
nightly-rocm-2026-09-09-musa
nightly-rocm-2026-09-09-rocm
nightly-rocm-2026-09-09-rocm-torch210
nightly-rocm-2026-09-09-xpu
operator-latest
operator-nightly-latest
operator-v0.*
operator-v0.1.1
operator-v0.4.8rc1
operator-v0.5.0
operator-v0.5.0rc1
operator-v0.5.0rc2
operator-v0.5.0rc3
operator-v0.5.1
operator-v0.5.1rc1
operator-v0.5.2
operator-v0.5.3
operator-v0.5.3rc1
operator-v0.5.4
v0.*
v0.1.0-alpha
v0.1.1-alpha
v0.1.2-alpha
v0.1.3-alpha
v0.1.4-alpha
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.1.post1
v0.3.10
v0.3.10.post1
v0.3.10post2
v0.3.11
v0.3.12
v0.3.13
v0.3.14
v0.3.15
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.3.9post1
v0.3.9post2
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.4-cu13
v0.4.5
v0.4.5-cu129
v0.4.6
v0.4.6-cu129
v0.4.7
v0.4.7-cu129
v0.4.8rc3
v0.4.8rc3-cu129
v0.4.8rc4
v0.4.8rc4-cu129
v0.5.0
v0.5.0-cu129
v0.5.0rc1
v0.5.0rc1-cu129
v0.5.1
v0.5.1-cu129
v0.5.1rc1
v0.5.1rc1-cu129
v0.5.1rc2
v0.5.1rc2-cu129
v0.5.2
v0.5.2-cu129
v0.5.2rc1
v0.5.2rc1-cu129
v0.5.3
v0.5.3-cu129
v0.5.3-rocm
v0.5.3.rc3
v0.5.3.rc3-rocm
v0.5.3rc1
v0.5.3rc1-cu129
v0.5.3rc1-rocm
v0.5.3rc2
v0.5.3rc2-cu129
v0.5.3rc2-rocm
v0.5.3rc3
v0.5.3rc3-cu129
v0.5.3rc3-rocm
v0.5.3rc4
v0.5.3rc4-cu129
v0.5.3rc4-rocm
v0.5.4
v0.5.4-cu129
v0.5.4rc1
v0.5.4rc1-cu129
v0.5.4rc1-rocm
v0.5.4rc2
v0.5.4rc2-cu129
v0.5.4rc2-rocm
v0.5.4rc3
v0.5.4rc3-cu129
v0.5.4rc4
v0.5.4rc4-cu129
v0.5.4rc4-rocm
v0.5.4rc5
v0.5.4rc5-cu129
v0.5.5
v0.5.5-cu129
v0.5.5-musa
v0.5.5-rocm
v0.5.5-rocm-torch210
v0.5.5-xpu
v0.5.5rc1
v0.5.5rc1-cu129
v0.5.5rc1-rocm
v0.5.5rc1-xpu
v0.5.5rc2
v0.5.5rc2-cu129
v0.5.5rc2-rocm
v0.5.5rc2-rocm-torch210
v0.5.5rc2-xpu
v0.5.5rc3
v0.5.5rc3-cu129
v0.5.5rc3-rocm
v0.5.5rc3-rocm-torch210
v0.5.5rc3-xpu
v0.5.5rc4
v0.5.5rc4-cu129
v0.5.5rc4-rocm
v0.5.5rc4-rocm-torch210
v0.5.5rc4-xpu
v0.5.5rc5
v0.5.5rc5-cu129
v0.5.5rc5-musa
v0.5.5rc5-rocm
v0.5.5rc5-rocm-torch210
v0.5.5rc5-xpu
v0.5.5rc6
v0.5.5rc6-cu129
v0.5.5rc6-rocm-torch210
v0.5.5rc7
v0.5.5rc7-cu129
v0.5.5rc7-musa
v0.5.5rc7-rocm
v0.5.5rc7-rocm-torch210
v0.5.5rc7-xpu

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107205.json"