Mmastodon TechnologyAI first seen 5 h ago, last 5 h ago, peak #1
Three unpatched critical flaws disclosed in LightLLM
Original: 🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVE
Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.
Why now: A critical 9.8 unauthenticated remote code execution flaw with no patch poses an immediate risk to anyone running LightLLM instances online.
LightLLMCVE-2026-103040CVE-2026-103041CVE-2026-103042RPyC
Rank over time, top of the chart is #1. 2 snapshots from 5 h ago to 5 h ago.
Evidence
- 🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVE-2026-103041 (CVSS 9.8) — unauthenticated RCE, embed cache RPyC CVE-2026-103042 (CVSS 7.5) — memory exhaustion, NCCL control channel Root cause:… · threataft@infosec.exchange · 4
API: https://socialmediatrends-api.osmike.com/v1/trends/442053