CVE-2026-93839

Source
https://cve.org/CVERecord?id=CVE-2026-93839
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93839.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93839
Published
2026-09-18T19:06:05Z
Modified
2026-09-19T03:47:29Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint
Details

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93839.json"
}
References

Affected packages

Git / github.com/modeltc/lightllm

Affected ranges

Type
GIT
Repo
https://github.com/modeltc/lightllm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.2.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.0.0
v1.0.1
v1.1.0
v1.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93839.json"