Act nowDisclosed

Advisory · CVE-2026-103764

Mooncake transfer engine allows unauthenticated arbitrary memory read and write

Mooncake transfer engine before 0.3.13 trusts pointer values in TCP transport session headers, letting unauthenticated attackers read or overwrite process memory, including KV cache contents.

Vendor
kvcache-ai
Product
Mooncake transfer engine
Identifier / CWE
CVE-2026-103764
CWE-822
Action timing
Immediate
ELI5

Explain it like I’m five

The transfer engine reads a memory address straight off an attacker's request label and fetches or overwrites whatever lives there, no questions asked. Hand it an address holding prompts, cached model data, or code, and it will hand back or trample the contents.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Crafted session header

    An unauthenticated attacker connects to the TCP transport data port and sends a SessionHeader carrying arbitrary addr and size values with a READ or WRITE opcode.

  2. 02Pointer trusted blindly

    ServerSession::readHeader dereferences the supplied pointer without validating it against any registered memory region.

  3. 03Arbitrary memory access

    READ returns process memory such as KV cache entries, prompts, and in-process secrets; WRITE overwrites live process memory.

  4. 04Path to code execution

    Targeted memory corruption can be steered toward code execution inside the transfer engine process.

What happened

VulnCheck disclosed CVE-2026-103764 on October 2, 2026, rated critical at CVSS 9.8 (v3.1). Mooncake transfer engine releases before 0.3.13 are affected, including the 0.3.x line used as the KV cache data plane in disaggregated LLM inference stacks.

The TCP transport accepts a session header containing a raw memory address and length. ServerSession::readHeader dereferences that pointer without checking the address belongs to a registered buffer, so any client that can reach the data port can read or write arbitrary process memory without authentication. Read access can expose KV cache contents, live prompts, and secrets held in the process; write access corrupts memory toward code execution.

Mooncake 0.3.13, released August 26, 2026, contains the fix.

What to do

  1. Inventory Mooncake transfer engine deployments, including vLLM or SGLang inference clusters and standalone KV cache services.
  2. Upgrade every instance older than 0.3.13 to 0.3.13 or later.
  3. Restrict the TCP transport data port to trusted cluster networks only; it should never be reachable from untrusted networks or tenant workloads.
  4. Review transfer engine logs and network flows for connections to the data port from unexpected hosts, especially before the upgrade.
  5. If an unpatched instance was reachable from untrusted networks, treat KV cache contents, prompts, and any in-process credentials as potentially exposed and rotate secrets as needed.

Management note

This is an unauthenticated, internet-grade flaw in the data plane of a popular AI inference component. The KV cache it protects can hold user prompts and model state, so patching and network scoping belong in the same change window.