CVE-2026-103764: Kvcache-Ai Mooncake

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.

Affected products

  • Kvcache-Ai Mooncake: before 0.3.13 (fixed in 0.3.13)

Published 2026-10-02. Last modified 2026-10-02.