DEV Community

threataft
threataft

Posted on Originally published at threataft.com

LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

Two unauthenticated CVSS 9.8 RCEs in LightLLM — the LLM serving framework
used with LLaMA, Mistral, and Qwen deployments. No patch confirmed. All
versions through 1.2.0 are affected.

The CVEs

CVE CVSS Type Vector
CVE-2026-103040 9.8 Pickle deserialization RCE Router profiler RPyC service
CVE-2026-103041 9.8 Pickle deserialization RCE Embed cache RPyC service
CVE-2026-103042 7.5 Memory exhaustion DoS NCCL control channel

What happened

Both RCE flaws share the same root cause: unauthenticated RPyC services
passing untrusted input directly to pickle.loads(). Python's pickle module
executes arbitrary code on deserialization — no authentication, no
validation, full RCE with service privileges.

CVE-2026-103040 only fires when --enable_profiling is set. If you
don't need profiling, that flag should never be on in production.

CVE-2026-103041 affects multimodal deployments. The embed cache RPyC
service is exposed on all interfaces by default.

CVE-2026-103042 lets unauthenticated attackers call
exposed_set_value on the NCCL control channel without size limits,
growing the KV-transfer worker's memory until the node crashes.

Why this hits hard in production

A compromised LightLLM node exposes every user prompt, model weight, and
API key the service processes. These aren't dev tools — they're inference
servers running in production AI stacks. The pickle deserialization pattern
is well-understood and preventable. It shouldn't be appearing in frameworks
deployed at this scale.

What to do now

  1. Don't enable --enable_profiling in production — removes CVE-2026-103040 attack surface entirely
  2. Firewall the RPyC ports — profiler and embed cache services should never be internet-exposed
  3. Restrict --pd_trans_mode nccl — NCCL control channel to trusted nodes only
  4. Apply memory limits — cgroups or container resource quotas to cap exhaustion impact
  5. Watch for patches — no fix confirmed yet for 1.2.0

Full technical breakdown with CVSS vectors, CWE classifications, and full
mitigation checklist:


LightLLM Mass Disclosure — CVE-2026-103040, CVE-2026-103041, CVE-2026-103042

Originally published at ThreatAft

Top comments (0)