← Back to CVE List
Vulnerability Intelligence Report
Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport

CVE-2026-103764

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-822 ↗Untrusted Pointer Dereference

Affected Products & Versions

Vendor Product Affected Versions
kvcache-ai Mooncake 0 < 0.3.13 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.636%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-10-01T10:39:47
Published2026-10-01T23:19:57
Patch Date2026-10-01
Last Updated2026-10-02T18:22:06

LINK COPIED TO CLIPBOARD