search
CVE-2026-103042
Trends
- 1Three unpatched critical flaws disclosed in LightLLM▼🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVE
Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.
- 2New CVE Alert Issued for ModelTC LightLLM●CVE Alert: CVE-2026-103042 - ModelTC - LightLLM - https://www. redpacketsecurity.com/cve-aler t-cve-2026-103042-modeltc-
A security advisory has been published for CVE-2026-103042, a vulnerability affecting LightLLM, the large language model inference server developed by ModelTC. Threat intelligence accounts are circulating the alert to warn organisations running the software to review the flaw and check whether patches or mitigations are available.