← Back to CVE List
Vulnerability Intelligence Report
Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString

CVE-2026-104433

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.37%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-125 ↗Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
kvcache-ai Mooncake 0 < 0.3.12 (affected), 0.3.12 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.366%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-10-02T00:50:26
Published2026-10-02T23:28:44
Patch Date2026-10-02
Last Updated2026-10-05T16:08:38

LINK COPIED TO CLIPBOARD