CVE-2026-103765
Received Received - Intake

Unauthenticated Metadata Access in Mooncake

Vulnerability report for CVE-2026-103765, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kvcache-ai mooncake 0.3.13.post1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103765 is a missing authentication vulnerability in Mooncake's HTTP metadata server through version 0.3.13.post1. The /metadata endpoint lacks authentication, allowing unauthenticated attackers to read, overwrite, or delete transfer engine metadata keys. Attackers can poison segment descriptors like tcp_data_port or recreate rpc_meta entries to redirect KV cache transfers to malicious listeners or cause memory exhaustion.

Detection Guidance

Check if the Mooncake HTTP metadata server is running on your network by scanning for open ports typically used by the service. Inspect network traffic for unauthenticated GET, PUT, or DELETE requests to the /metadata endpoint. Look for unusual RPC metadata modifications or segment descriptor poisoning attempts in logs.

Impact Analysis

This vulnerability allows attackers to read sensitive metadata, redirect data transfers to attacker-controlled systems, overwrite or delete critical metadata, and cause server memory exhaustion. It could lead to data exfiltration, service disruption, or unauthorized access to cached data without detection.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and integrity. It enables unauthorized access to sensitive data (GDPR Article 32, HIPAA Security Rule), allows data exfiltration without detection, and could result in unauthorized modifications to critical system metadata, undermining audit controls and data integrity.

Mitigation Strategies

Immediately disable the HTTP metadata server if not critical. Implement network-level access controls to restrict access to the /metadata endpoint. Monitor for unauthorized modifications to metadata keys and segment descriptors. Consider patching once available or migrating to a secure alternative.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103765. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart