CVE-2026-103042
published 2026-09-29CVE-2026-103042: LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.52%
42.2th percentile
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| modeltc | lightllm | <= 1.2.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker m
ghsa_unreviewed·2026-09-30
CVE-2026-103042 [HIGH] CWE-770 LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker m
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
VulDB
ModelTC LightLLM up to 1.2.0 NCCL control channel exposed_set_value memory allocation
vuldb·2026-09-30·CVSS 7.5
CVE-2026-103042 [HIGH] ModelTC LightLLM up to 1.2.0 NCCL control channel exposed_set_value memory allocation
A vulnerability categorized as problematic has been discovered in ModelTC LightLLM up to 1.2.0. Affected by this vulnerability is the function exposed_set_value of the component NCCL control channel. Such manipulation leads to uncontrolled memory allocation.
This vulnerability is listed as CVE-2026-103042. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ModelTC/LightLLMhttps://github.com/ModelTC/LightLLM/issues/1595https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/base_kv_move_manager.py#L121-L122https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L416-L420https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L474-L485https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-memory-exhaustion-via-nccl-control-channel-set-valuehttps://github.com/ModelTC/LightLLM/issues/1595
2026-09-29
Published