Mooncake flaws rated up to 9.8 allow unauthenticated memory read/write
Four vulnerabilities were found in Mooncake's KV cache transfer engine. CVE-2026-103764 (CVSS 9.8) lets a crafted TCP packet read and write arbitrary process memory without authentication; it is fixed in Mooncake 0.3.13. The other three affect versions through 0.3.13.post1 with no confirmed fix yet.
- CVE-2026-103764 (CVSS 9.8): untrusted pointer dereference in ServerSession::readHeader
- CVE-2026-103765 (CVSS 9.4): missing auth in HTTP /metadata handler
- CVE-2026-103761 (CVSS 7.5) and CVE-2026-103760 (CVSS 5.9) remain unfixed
- Only CVE-2026-103764 is patched, in Mooncake 0.3.13
Read next
Security