Advisory · CVE-2026-103764
Mooncake transfer engine allows unauthenticated arbitrary memory read and write
Mooncake transfer engine before 0.3.13 trusts pointer values in TCP transport session headers, letting unauthenticated attackers read or overwrite process memory, including KV cache contents.
- Vendor
- kvcache-ai
- Product
- Mooncake transfer engine
- Identifier / CWE
- CVE-2026-103764
CWE-822 - Action timing
- Immediate
Explain it like I’m five
The transfer engine reads a memory address straight off an attacker's request label and fetches or overwrites whatever lives there, no questions asked. Hand it an address holding prompts, cached model data, or code, and it will hand back or trample the contents.
- 01Crafted session header
An unauthenticated attacker connects to the TCP transport data port and sends a SessionHeader carrying arbitrary addr and size values with a READ or WRITE opcode.
- 02Pointer trusted blindly
ServerSession::readHeader dereferences the supplied pointer without validating it against any registered memory region.
- 03Arbitrary memory access
READ returns process memory such as KV cache entries, prompts, and in-process secrets; WRITE overwrites live process memory.
- 04Path to code execution
Targeted memory corruption can be steered toward code execution inside the transfer engine process.
What happened
VulnCheck disclosed CVE-2026-103764 on October 2, 2026, rated critical at CVSS 9.8 (v3.1). Mooncake transfer engine releases before 0.3.13 are affected, including the 0.3.x line used as the KV cache data plane in disaggregated LLM inference stacks.
The TCP transport accepts a session header containing a raw memory address and length. ServerSession::readHeader dereferences that pointer without checking the address belongs to a registered buffer, so any client that can reach the data port can read or write arbitrary process memory without authentication. Read access can expose KV cache contents, live prompts, and secrets held in the process; write access corrupts memory toward code execution.
Mooncake 0.3.13, released August 26, 2026, contains the fix.
What to do
- Inventory Mooncake transfer engine deployments, including vLLM or SGLang inference clusters and standalone KV cache services.
- Upgrade every instance older than 0.3.13 to 0.3.13 or later.
- Restrict the TCP transport data port to trusted cluster networks only; it should never be reachable from untrusted networks or tenant workloads.
- Review transfer engine logs and network flows for connections to the data port from unexpected hosts, especially before the upgrade.
- If an unpatched instance was reachable from untrusted networks, treat KV cache contents, prompts, and any in-process credentials as potentially exposed and rotate secrets as needed.
Management note
This is an unauthenticated, internet-grade flaw in the data plane of a popular AI inference component. The KV cache it protects can hold user prompts and model state, so patching and network scoping belong in the same change window.