CVE-2026-10813
A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of t
CVSS
3.6
Bajo
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Publicado: 4 jun 2026 · Última mod.: 22 jul 2026 · CWE-327 · CWE-328
0.1%EPSS · 30 días0.1%
2026-08-202026-09-18
A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
- github.comhttps://github.com/LMCache/LMCache/
- github.comhttps://github.com/LMCache/LMCache/issues/3301
- github.comhttps://github.com/LMCache/LMCache/pull/2932
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10813
- vuldb.comhttps://vuldb.com/submit/831641
- vuldb.comhttps://vuldb.com/vuln/368261
- vuldb.comhttps://vuldb.com/vuln/368261/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-814383.7 BAJ7.6%
——2Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.6hCVE-2025-365914.4 MED1.5%
——0Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.2dCVE-2026-15638—10.4%
——3An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.4hCVE-2026-119297.5 ALT5.7%
——2IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.2dCVE-2026-174678.2 ALT20.5%
——6IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.2dCVE-2026-818228.4 ALT0.3%
——0The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.7d