JFrog Reports Critical LMCache Flaw CVE-2026-105192, a CVSS 9.8 Pickle Deserialization Bug in Multiprocess Mode, With No Fixed Version as of October 7
JFrog's October 7 advisory rates LMCache's CVE-2026-105192 at CVSS 9.8 and lists no fixed release; a fix pull request opened October 11 was still open that day.