CRITICAL 9.3 NVD
CVE-2026-103764
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
References
- https://github.com/kvcache-ai/Mooncake
- https://github.com/kvcache-ai/Mooncake/blob/6041a609a8c3af35e778f70db344f145c2914980/moonc
- https://github.com/kvcache-ai/Mooncake/commit/a2933849417259e562fc9cbad63c618d464dfb2d
- https://github.com/kvcache-ai/Mooncake/issues/4441
- https://github.com/kvcache-ai/Mooncake/releases/tag/v0.3.13
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-02 via NVD.
Risk Timeline
CVE Disclosed2026-10-02 · -1 days ago
Remediation Resources
vulnfeed aggregates 9442 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.