MikeTrendsTrends right now

Mmastodon TechnologyAI first seen 6 h ago, last 6 h ago, peak #1

Three unpatched critical flaws disclosed in LightLLM

Original: 🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVE

Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

Why now: A critical 9.8 unauthenticated remote code execution flaw with no patch poses an immediate risk to anyone running LightLLM instances online.

LightLLMCVE-2026-103040CVE-2026-103041CVE-2026-103042RPyC

Open on mastodon →

Rank over time, top of the chart is #1. 2 snapshots from 6 h ago to 6 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/442053