{"id":"CVE-2026-107207","title":"LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts","summary":"LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries v…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-306"],"vendor":"LMCache","product":"LMCache","affected":["LMCache <= 0.5.5"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:17:45.617","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107207","references":[{"url":"https://github.com/LMCache/LMCache","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py#L411-L428","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/lmcache_frontend/app.py#L567-L604","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LMCache/LMCache/issues/5512","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-frontend-node-catalog-allows-ssrf-allowlist-bypass","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T16:38:22.225Z","slug":"CVE-2026-107207","body":"## Overview\n\nLMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}