Vulnerability Intelligence Report
Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
CVE-2026-103764
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-822 ↗Untrusted Pointer Dereference
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| kvcache-ai | Mooncake | 0 < 0.3.13 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.636%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-10-01T10:39:47 |
| Published | 2026-10-01T23:19:57 |
| Patch Date | 2026-10-01 |
| Last Updated | 2026-10-02T18:22:06 |
Community Chatter & Buzz