chiprook
← Security
SecurityOctober 2, 2026, 10:15

Mooncake flaws rated up to 9.8 allow unauthenticated memory read/write

Four vulnerabilities were found in Mooncake's KV cache transfer engine. CVE-2026-103764 (CVSS 9.8) lets a crafted TCP packet read and write arbitrary process memory without authentication; it is fixed in Mooncake 0.3.13. The other three affect versions through 0.3.13.post1 with no confirmed fix yet.

Mooncake flaws rated up to 9.8 allow unauthenticated memory read/write
#Mooncake
Read next
Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws

Security

Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution

Security

IBM patches 12 flaws in MQ and Langflow OSS, three rated 9.8

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8