{"id":"CVE-2026-107207","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-107207","summary":"LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by…","details":"LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.","published":"2026-10-07T16:17:45.617","modified":"2026-10-07T16:17:45.617","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/LMCache/LMCache"},{"type":"WEB","url":"https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py#L411-L428"},{"type":"WEB","url":"https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py#L567-L604"},{"type":"WEB","url":"https://github.com/LMCache/LMCache/issues/5512"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-frontend-node-catalog-allows-ssrf-allowlist-bypass"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-07T16:17:45.617"}}