Vulnerability Intelligence Report
Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString
CVE-2026-104433
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.37%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-125 ↗Out-of-bounds Read
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| kvcache-ai | Mooncake | 0 < 0.3.12 (affected), 0.3.12 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.366%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-10-02T00:50:26 |
| Published | 2026-10-02T23:28:44 |
| Patch Date | 2026-10-02 |
| Last Updated | 2026-10-05T16:08:38 |
Community Chatter & Buzz