CVE-2026-103042: LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_value
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pdtransmode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposedsetvalue method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
Affected Software
Event History
Frequently Asked Questions
Which deployments are in scope?
The issue is identified in LightLLM deployments through version 1.2.0 that are started with --pd_trans_mode nccl. The available information does not establish that other transfer modes are affected.
Does an attacker need credentials or user interaction to trigger the failure?
No. The vulnerability is described as unauthenticated, with no privileges or user interaction required; an attacker can invoke the exposed_set_value method to add unbounded key-value pairs.