CVE-2026-107207: Lmcache

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.

Affected products

  • Lmcache Lmcache: up to and including 0.5.5

Published 2026-10-07. Last modified 2026-10-08.