CVE-2026-103764
Received Received - Intake

Memory Corruption in Mooncake Transfer Engine

Vulnerability report for CVE-2026-103764, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moonshot_ai mooncake_transfer_engine to 0.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated arbitrary memory read/write issue in the Mooncake transfer engine before version 0.3.13. It stems from an untrusted pointer dereference in ServerSession::readHeader that allows attackers to send crafted SessionHeader packets with arbitrary memory addresses and sizes using READ or WRITE opcodes via the TCP transport data port. This can lead to disclosure of sensitive data like KV cache contents, prompts, and secrets, or memory corruption that may result in arbitrary code execution.

Detection Guidance

Check if Mooncake transfer engine version is below 0.3.13 by running: mooncake-transfer-engine --version. Scan for open TCP ports in the 15000-17000 range using netstat -tulnp | grep -E '15000|16000|17000'. Monitor for unauthorized memory access attempts in logs or use network traffic analysis tools like tcpdump to inspect malformed SessionHeader packets.

Impact Analysis

If you use Mooncake transfer engine versions before 0.3.13, attackers on the same network can exploit this flaw to read or write arbitrary memory in the engine process. This could allow them to steal sensitive data such as prompts, secrets, or KV cache contents, corrupt memory to cause crashes or execute malicious code, and potentially gain control over the system hosting the Mooncake service.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of sensitive data such as personally identifiable information (PII) or protected health information (PHI), which are covered under regulations like GDPR and HIPAA. A successful exploit may result in data breaches, violating compliance requirements for data confidentiality and security, potentially leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade Mooncake transfer engine to version 0.3.13 or later immediately. If upgrading is not possible, disable the TCP transport data port or restrict access via firewall rules to trusted IPs only. Ensure no sensitive data is exposed on the vulnerable port by reviewing network configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103764. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart