CVE-2026-104433
Received Received - Intake

Out-of-Bounds Read in Mooncake Transfer Engine

Vulnerability report for CVE-2026-104433, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moonshot_ai mooncake to 0.3.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read flaw in Mooncake's transfer engine before version 0.3.12. It exists in the readString function of include/common.h. Attackers can exploit it by sending a zero-length handshake frame to the service's handshake port, causing a crash. The issue allows unauthenticated remote attackers to terminate hosting processes like SGLang inference servers by sending an eight-byte frame.

Detection Guidance

Check if Mooncake transfer engine version is below 0.3.12 by running: mooncake-transfer-engine --version. Monitor for crashes in SGLang or vLLM processes after network connections to ports 15000-17000. Use tcpdump or Wireshark to inspect for zero-length handshake frames sent to these ports.

Impact Analysis

This vulnerability can lead to denial-of-service (DoS) conditions. Unauthenticated attackers can remotely crash critical services such as SGLang or vLLM inference servers by sending malformed handshake frames. This forces service restarts, disrupting availability and potentially causing downtime in production environments.

Compliance Impact

This vulnerability primarily impacts service availability by crashing the Mooncake transfer engine, which could disrupt systems handling sensitive data. For GDPR, it may affect data processing continuity and availability requirements. For HIPAA, it could compromise service uptime for systems managing protected health information. However, the CVE does not explicitly detail compliance impacts beyond service disruption.

Mitigation Strategies

Upgrade Mooncake transfer engine to version 0.3.12 or later immediately. Block external access to ports 15000-17000 using firewalls until patched. Restart affected services like SGLang or vLLM after upgrading to ensure the fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104433. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart