HIGH 8.7 NVD
CVE-2026-103042
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated a
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
References
- https://github.com/ModelTC/LightLLM
- https://github.com/ModelTC/LightLLM/issues/1595
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_ba
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_ba
- https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_ba
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.