OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103042

HIGH · CVSS 7.5 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

LightLLM versions up to 1.2.0 are vulnerable to a memory exhaustion issue in the NCCL control channel, which can be exploited by unauthenticated attackers to overload KV-transfer worker memory. By invoking the exposed_set_value method, attackers can store unlimited key-value pairs, leading to worker process crashes and potential node failures. Organizations utilizing LightLLM should prioritize patching this vulnerability to mitigate the risk of service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103042
Severity
HIGH
CVSS
7.5
EPSS
0.52%

Original NVD Description

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.