Deserialization of Untrusted Data Affecting lmcache-cuda-12.8 package, versions <0.5.3-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.86% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-LMCACHECUDA128-18769576
  • published14 Aug 2026
  • disclosed1 Jul 2026

Introduced: 1 Jul 2026

CVE-2026-57516  (opens in a new tab)
CWE-502  (opens in a new tab)

How to fix?

Upgrade Chainguard lmcache-cuda-12.8 to version 0.5.3-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream lmcache-cuda-12.8 package and not the lmcache-cuda-12.8 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decoder() function in webdataset_datasource.py unconditionally calls pickle.loads() on tar entries with .pkl/.pickle extensions and torch.load() with weights_only=False on .pt/.pth entries, executing arbitrary code inside Ray remote workers on every worker that processes the malicious archive.

CVSS Base Scores

version 3.1