HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-103042 — LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL co...
·Source: NIST NVD
Updated:
Executive Summary
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
Analysis
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure. CVSS Score: 7.5. Published: 2026-09-29T23:17:21.830.